onsdag 3 juli 2013

Consideration when using post/put and spnego/kerberos


From RFC(http://tools.ietf.org/html/rfc4559):

 When using the SPNEGO HTTP authentication facility with client-
   supplied data such as PUT and POST, the authentication should be
   complete between the client and server before sending the user data.
   The return status from the gss_init_security_context will indicate
   that the security context is complete.  At this point, the data can
   be sent to the server.

What does this mean?
This actually means that if you have a loadbalancer/reverse proxy/similar(tmg/cisco-ace/iis/apache/nginx)) that supports
spnego/kerberos running towards a middleware system that doesn't(but replies ok whenever an authentication header is passed - or not) - post requests won't work.

The reverse proxy will send an empty post request with an headers, expecting an authentication negotiation from the server to properly authenticate before sending a new post with the actual data.

Seen in action With Hybris and Microsoft forefront TMG.