X-Git-Url: https://git.argeo.org/?a=blobdiff_plain;f=org.argeo.cms%2Fsrc%2Forg%2Fargeo%2Fcms%2Finternal%2Fkernel%2Fjaas.cfg;h=018c1bf9ca947f1376b045e9e94484fda498376e;hb=6338d85d3f970dd0eb8845693ddad90a93b99d03;hp=4c7ebb328c7b7f766e3278011629b1c5ce2744b8;hpb=54cba9d97464302cbcfad9d8a57cb23a17bdddb7;p=lgpl%2Fargeo-commons.git diff --git a/org.argeo.cms/src/org/argeo/cms/internal/kernel/jaas.cfg b/org.argeo.cms/src/org/argeo/cms/internal/kernel/jaas.cfg index 4c7ebb328..018c1bf9c 100644 --- a/org.argeo.cms/src/org/argeo/cms/internal/kernel/jaas.cfg +++ b/org.argeo.cms/src/org/argeo/cms/internal/kernel/jaas.cfg @@ -1,34 +1,37 @@ USER { - org.argeo.cms.auth.HttpLoginModule requisite; - org.argeo.cms.auth.UserAdminLoginModule requisite; - org.argeo.cms.auth.NodeUserLoginModule requisite; + org.argeo.cms.auth.HttpSessionLoginModule sufficient; + org.argeo.cms.auth.SpnegoLoginModule optional; + com.sun.security.auth.module.Krb5LoginModule optional tryFirstPass=true; + org.argeo.cms.auth.UserAdminLoginModule sufficient; }; ANONYMOUS { - org.argeo.cms.auth.UserAdminLoginModule requisite anonymous=true; - org.argeo.cms.auth.NodeUserLoginModule requisite; + org.argeo.cms.auth.HttpSessionLoginModule sufficient; + org.argeo.cms.auth.AnonymousLoginModule sufficient; }; DATA_ADMIN { org.argeo.cms.auth.DataAdminLoginModule requisite; }; -SYSTEM { +NODE { + com.sun.security.auth.module.Krb5LoginModule optional + keyTab="${osgi.instance.area}node/krb5.keytab" + useKeyTab=true + storeKey=true; org.argeo.cms.auth.DataAdminLoginModule requisite; }; - -HARDENED_KERNEL { - com.sun.security.auth.module.UnixLoginModule requisite; - com.sun.security.auth.module.KeyStoreLoginModule requisite keyStoreURL="${osgi.instance.area}/node.p12" keyStoreType=PKCS12; -}; - KEYRING { org.argeo.cms.auth.KeyringLoginModule required; }; SINGLE_USER { - com.sun.security.auth.module.UnixLoginModule requisite; + com.sun.security.auth.module.Krb5LoginModule optional + principal="${user.name}" + storeKey=true + useTicketCache=true + debug=true; org.argeo.cms.auth.SingleUserLoginModule requisite; };