stoty commented on code in PR #577:
URL: 
https://github.com/apache/httpcomponents-client/pull/577#discussion_r1747050129


##########
httpclient5/src/main/java/org/apache/hc/client5/http/auth/KerberosConfig.java:
##########
@@ -53,25 +49,28 @@ public enum Option {
 
     public static final KerberosConfig DEFAULT = new Builder().build();
 
-    private final Option stripPort;
-    private final Option useCanonicalHostname;
-    private final Option requestDelegCreds;
+    private final Option stripPort; //Effective default is ENABLE
+    private final Option useCanonicalHostname; //Effective default is ENABLE
+    private final Option requestDelegCreds; //Effective default is DISABLE
+    private final Option requestMutualAuth; //Effective default is DISABLE

Review Comment:
   All I can came up with is:
   - GSS does not default to mutual auth
   - Backwards compatibility
   
   I would at least leave an option to disable this, so that there is an out 
for very broken cases.
   Of course there is also a case for forcing users to clean up their 
potentially broken setup.



##########
httpclient5/src/main/java/org/apache/hc/client5/http/auth/StandardAuthScheme.java:
##########
@@ -66,20 +66,12 @@ private StandardAuthScheme() {
 
     /**
      * SPNEGO authentication scheme as defined in RFC 4559 and RFC 4178.
-     *
-     * @deprecated Do not use. The GGS based experimental authentication 
schemes are no longer
-     * supported. Consider using Basic or Bearer authentication with TLS 
instead.
      */
-    @Deprecated
     public static final String SPNEGO = "Negotiate";
 
     /**
      * Kerberos authentication scheme as defined in RFC 4120.
-     *
-     * @deprecated Do not use. The GGS based experimental authentication 
schemes are no longer
-     * supported. Consider using Basic or Bearer authentication with TLS 
instead.
      */
-    @Deprecated
     public static final String KERBEROS = "Kerberos";

Review Comment:
   OK



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@hc.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@hc.apache.org
For additional commands, e-mail: dev-h...@hc.apache.org

Reply via email to