• No replies
Detelin Yordanov
Detelin Yordanov
2 Posts

Pinned topic JGSS Kerberos mechanism always uses mutual authentication

‏2013-08-28T20:36:28Z |

Hi everyone,

  We are using JGSS Kerberos mechanism to obtain a Kerberos service ticket against a Windows 2008 Server Active directory KDC and noticed that even though we explicitly request not to use mutual authentication via GSSContext.requestMutualAuth(false), the GSSContext initiation still uses mutual authentication and thus the context is not established with the first call to initSecContext but seem to additionally require the KRB_AP_REP response token is supplied.

Is our assumption correct and if so, is it possible to disable mutual authentication in some other way? We are using IBM Java 1.7 SR4 on AIX.