]> git.argeo.org Git - lgpl/argeo-commons.git/blobdiff - org.argeo.cms/src/org/argeo/cms/internal/kernel/jaas-ipa.cfg
Refactor JCR
[lgpl/argeo-commons.git] / org.argeo.cms / src / org / argeo / cms / internal / kernel / jaas-ipa.cfg
index 33c556f57cbe411e3cc604d1807ab5135e74311b..52bf4c37567456048d55a19d441dd27d21ae6d09 100644 (file)
@@ -1,16 +1,30 @@
 USER {
-    com.sun.security.auth.module.Krb5LoginModule required clearPass=true;
+    org.argeo.cms.auth.HttpSessionLoginModule sufficient;
+    org.argeo.cms.auth.SpnegoLoginModule optional;
+    com.sun.security.auth.module.Krb5LoginModule optional;
     org.argeo.cms.auth.IpaLoginModule requisite;
 };
 
-ANONYMOUS {
-    org.argeo.cms.auth.UserAdminLoginModule requisite anonymous=true;
+DATA_ADMIN {
+    org.argeo.cms.auth.DataAdminLoginModule requisite;
 };
 
-DATA_ADMIN {
+NODE {
+    com.sun.security.auth.module.Krb5LoginModule optional
+     keyTab="${osgi.instance.area}node/krb5.keytab" 
+     useKeyTab=true
+     storeKey=true
+     debug=true;
     org.argeo.cms.auth.DataAdminLoginModule requisite;
 };
 
+SINGLE_USER {
+    com.sun.security.auth.module.Krb5LoginModule optional
+     storeKey=true
+     debug=true;
+    org.argeo.cms.auth.SingleUserLoginModule requisite;
+};
+
 KEYRING {
     org.argeo.cms.auth.KeyringLoginModule required;
 };
@@ -18,3 +32,4 @@ KEYRING {
 Jackrabbit {
    org.argeo.security.jackrabbit.SystemJackrabbitLoginModule requisite;
 };
+