Question
data:image/s3,"s3://crabby-images/37998/379989cfbedeb915c0e43cbb48c01324601e9bcb" alt=""
ING Vysya Bank Ltd
NL
Last activity: 5 Jun 2018 13:52 EDT
Container Managed Authentication - Basic Authorization
Hi Team,
We have implemented container managed authentication in our organization. We got a security test done for our application and found that authorization header has been set to Basic and username and password are base64 encoded. Its very easy to decode the username and password and which is an security threat for the application.
Can you help how to disable basic authorization and what are the secured types we can use.
Solutions Tried:
We can enable form based authentication in web.xml by modifying the below tag
Regards
Manju