  | Mailing List | | Home | | Forum Home | | JBoss - Java Application Server | | Tomcat - JSP/Servlet container | | Struts - A MVC web framework | | iText - An open source PDF Java Library | | JDOM - JDOM XML Parser | | JSP - A mailing list about Java Server Pages specification and reference | | J2EE - A mailing list for Java(tm) 2 Platform, Enterprise Edition | | J2EE Pattern - An interest list for Sun Java Center J2EE Pattern Catalog | | Servlet - A mailing list for discussion about Sun Microsystem's Java Servlet API Technology | |
Struts & Hibernate
|
|
|
  | | | Subject: - mapping principals with digital certificates | Subject: - mapping principals with digital certificates 2007-10-01 - By oconesa
Back We have configured JAAS to authenticate users using digital certificates and roles stored in a database. It work fine, but we have a problem with the "Principal".
By default, when you use a digital certificate in JAAS, the Principal is the "DN:Distinguished Name" of the user certificate. But we want to map this Principal with another more simple like "user1", because the DN is a long text.
In the login-config.xml we use:
<application-policy name = "app1"> <login-module code = "org.jboss.security.auth.spi .DatabaseCertLoginModule" flag = "required"> <module-option name = "password-stacking">useFirstPass</module -option> <module-option name = "securityDomain">java:/jaas/jmx-console< /module-option> <module-option name = "verifier">org.jboss.security.auth.certs .AnyCertVerifier</module-option> <module-option name = "dsJndiName">java:/MySqlDS</module-option> <module-option name = "rolesQuery">SELECT Role, 'Roles' FROM Roles WHERE ID=?</module-option> </login-module> </application-policy>
View the original post : http://www.jboss.com/index.html?module=bb&op=viewtopic &p=4090110#4090110
Reply to the post : http://www.jboss.com/index.html?module=bb&op=posting&mode =reply&p=4090110 __ ____ ____ ____ ____ ____ ____ ____ ____ ____ jboss-user mailing list jboss-user@(protected) https://lists.jboss.org/mailman/listinfo/jboss-user
|
|
 |