[ https://issues.apache.org/jira/browse/HTTPCLIENT-1625?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17875352#comment-17875352 ]
Istvan Toth commented on HTTPCLIENT-1625: ----------------------------------------- Thank you [~michael-o]. Yes, the mutual auth problem was discussed here, I understand the problem. Even though the additional attack surface is small (cleartext HTTP/SPNEGO is already very insecure), I agree that we can't compromise there. I will look at libserf to how they implemented the client, as some choices are not obvious. How important is to maintain backwards compatibility for the AuthScheme interface ? I can probably do that with flags and default methods, but it won't be very pretty. > Completely overhaul GSS-API-based authentication backend > -------------------------------------------------------- > > Key: HTTPCLIENT-1625 > URL: https://issues.apache.org/jira/browse/HTTPCLIENT-1625 > Project: HttpComponents HttpClient > Issue Type: Task > Components: Documentation, HttpClient (classic) > Affects Versions: 4.5 > Reporter: Michael Osipov > Priority: Major > Labels: stuck, volunteers-wanted > > The current implementation does not reflect the way GSS-API-based > authentication should be done. It has several design flaws. > This is an umbrella task for: > 1. Deprecate all old classes > 2. Investigate how it has to be plugged into HttpClient > 3. Reimplement from scratch > 4. Thoroughly test all new stuff > 5. Rewrite documentation > Design notes are canonically available under: > https://wiki.apache.org/HttpComponents/IssueTracking/HTTPCLIENT-1625 -- This message was sent by Atlassian Jira (v8.20.10#820010) --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@hc.apache.org For additional commands, e-mail: dev-h...@hc.apache.org