此内容没有您所选择的语言版本。
Chapter 2. Application Server Configuration
To configure JBoss Negotiation to run on JBoss Enterprise Application Platform, you need to do the following:
- Extend the core authentication mechanism to support JBoss Negotiation (add the SPNEGO authenticator).
- Define the application security domain, which allows an application to communicate with the application server through the SPNEGOLoginModule.
- Define the server security domain, which allows the application server to authenticate itself to the KDC for the first time.
You may also need to configure the realm properties to allow the server to locate the authentication realm (Kerberos realm) if the server was not previously configured to do so.
JBoss Negotiation comes with Negotiation Toolkit, a web application, which allows you to test your SPNEGO setup. Consider using the application before testing on your own web applications (refer to Chapter 8, Negotiation Toolkit).
2.1. Adding the SPNEGO Authenticator 复制链接链接已复制到粘贴板!
复制链接链接已复制到粘贴板!
To add the
SPNEGO
authenticator to the core authentication mechanism, do the following:
- Open the
$JBOSS_HOME/server/PROFILE/deployers/jbossweb.deployer/META-INF/war-deployers-jboss-beans.xml
file for editing. - Locate the property
authenticators
. - Add the following entry to the property:
Copy to Clipboard Copied! Toggle word wrap Toggle overflow The key value is arbitrary; however, if you want to use the Negotiation Toolkit to test your server setup, make sure you use theSPNEGO
value as the tool works only with the SPNEGO authenticator with this name.