[ https://issues.apache.org/jira/browse/CXF-6279?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Sergey Beryozkin resolved CXF-6279. ----------------------------------- Resolution: Fixed > Introduce X509 Certificate Path validation utility code > -------------------------------------------------------- > > Key: CXF-6279 > URL: https://issues.apache.org/jira/browse/CXF-6279 > Project: CXF > Issue Type: Task > Components: JAX-RS Security > Reporter: Sergey Beryozkin > Assignee: Sergey Beryozkin > Fix For: 3.1.0, 3.0.5 > > > RS security code has two paths were the client certificates are not validated: > OAuth2 AccessTokenService where a client authenticating via 2-way TLS > requests a token and JOSE code where the chain is shipped in JOSE headers > (the latter has been highlighted by demo from Anders Rundgren). -- This message was sent by Atlassian JIRA (v6.3.4#6332)