X-Git-Url: https://git.argeo.org/?a=blobdiff_plain;f=org.argeo.cms%2Fsrc%2Forg%2Fargeo%2Fcms%2Finternal%2Fruntime%2Fjaas-ipa.cfg;h=0ef142f4aed07132db1d29a7145a1df5b5ede851;hb=4086635cfaa04c8a184124048794398b0ba96a55;hp=d0928aac0ff1482953ead65fedbf61b628b71239;hpb=9e3e4ceb38e36ee8d7b4287a60cd92f2b1a66a2a;p=lgpl%2Fargeo-commons.git diff --git a/org.argeo.cms/src/org/argeo/cms/internal/runtime/jaas-ipa.cfg b/org.argeo.cms/src/org/argeo/cms/internal/runtime/jaas-ipa.cfg index d0928aac0..0ef142f4a 100644 --- a/org.argeo.cms/src/org/argeo/cms/internal/runtime/jaas-ipa.cfg +++ b/org.argeo.cms/src/org/argeo/cms/internal/runtime/jaas-ipa.cfg @@ -1,8 +1,10 @@ USER { org.argeo.cms.auth.RemoteSessionLoginModule sufficient; org.argeo.cms.auth.SpnegoLoginModule optional; - com.sun.security.auth.module.Krb5LoginModule optional tryFirstPass=true; - org.argeo.cms.auth.UserAdminLoginModule sufficient; + com.sun.security.auth.module.Krb5LoginModule optional + tryFirstPass=true + storeKey=true; + org.argeo.cms.auth.UserAdminLoginModule required; }; ANONYMOUS { @@ -16,7 +18,7 @@ DATA_ADMIN { NODE { com.sun.security.auth.module.Krb5LoginModule optional - keyTab="${osgi.instance.area}node/krb5.keytab" + keyTab="${osgi.instance.area}private/krb5.keytab" useKeyTab=true storeKey=true; org.argeo.cms.auth.DataAdminLoginModule requisite; @@ -30,7 +32,8 @@ SINGLE_USER { com.sun.security.auth.module.Krb5LoginModule optional storeKey=true useTicketCache=true; - org.argeo.cms.auth.SingleUserLoginModule requisite; + org.argeo.cms.auth.SingleUserLoginModule required; + org.argeo.cms.auth.UserAdminLoginModule optional; }; Jackrabbit {