X-Git-Url: https://git.argeo.org/?a=blobdiff_plain;f=org.argeo.cms%2Fsrc%2Forg%2Fargeo%2Fcms%2Finternal%2Fkernel%2Fjaas-ipa.cfg;h=018c1bf9ca947f1376b045e9e94484fda498376e;hb=3152a0fe54d407b812cab4c141936227539a33b2;hp=52bf4c37567456048d55a19d441dd27d21ae6d09;hpb=b8da6ff850049dd39531c1e50f2eef38c4e3298e;p=lgpl%2Fargeo-commons.git diff --git a/org.argeo.cms/src/org/argeo/cms/internal/kernel/jaas-ipa.cfg b/org.argeo.cms/src/org/argeo/cms/internal/kernel/jaas-ipa.cfg index 52bf4c375..018c1bf9c 100644 --- a/org.argeo.cms/src/org/argeo/cms/internal/kernel/jaas-ipa.cfg +++ b/org.argeo.cms/src/org/argeo/cms/internal/kernel/jaas-ipa.cfg @@ -1,8 +1,13 @@ USER { org.argeo.cms.auth.HttpSessionLoginModule sufficient; org.argeo.cms.auth.SpnegoLoginModule optional; - com.sun.security.auth.module.Krb5LoginModule optional; - org.argeo.cms.auth.IpaLoginModule requisite; + com.sun.security.auth.module.Krb5LoginModule optional tryFirstPass=true; + org.argeo.cms.auth.UserAdminLoginModule sufficient; +}; + +ANONYMOUS { + org.argeo.cms.auth.HttpSessionLoginModule sufficient; + org.argeo.cms.auth.AnonymousLoginModule sufficient; }; DATA_ADMIN { @@ -13,23 +18,23 @@ NODE { com.sun.security.auth.module.Krb5LoginModule optional keyTab="${osgi.instance.area}node/krb5.keytab" useKeyTab=true - storeKey=true - debug=true; + storeKey=true; org.argeo.cms.auth.DataAdminLoginModule requisite; }; +KEYRING { + org.argeo.cms.auth.KeyringLoginModule required; +}; + SINGLE_USER { com.sun.security.auth.module.Krb5LoginModule optional + principal="${user.name}" storeKey=true + useTicketCache=true debug=true; org.argeo.cms.auth.SingleUserLoginModule requisite; }; -KEYRING { - org.argeo.cms.auth.KeyringLoginModule required; -}; - Jackrabbit { org.argeo.security.jackrabbit.SystemJackrabbitLoginModule requisite; }; -