小男孩‘自慰网亚洲一区二区,亚洲一级在线播放毛片,亚洲中文字幕av每天更新,黄aⅴ永久免费无码,91成人午夜在线精品,色网站免费在线观看,亚洲欧洲wwwww在线观看

分享

Webapp with CLIENT-CERT authentication method

 digitaldreamer 2007-01-14

The first prerequisite is tomcat running over SSL channel. Or you will get

 

 

Another prerequisite is to set the SSL port of Tomcat as mutual authentication. That way the UA will present your certificate to the server.

You will get this if no client certificate is provided.

 

The third prerequisite is the client must trust the server‘s certificate and vice verse. Firefox will raise this alter window if your certificate is not trusted by the server.

 

 

 


The web.xml of web app is,

<servlet-mapping>

<servlet-name>ProtectedServlet</servlet-name>

<url-pattern>/ProtectedByClientCert</url-pattern>

</servlet-mapping>

 

<security-role>

<role-name>members</role-name>

</security-role>

 

<security-constraint>

<web-resource-collection>

<web-resource-name>Resource protected by client cert</web-resource-name>

<url-pattern>/ProtectedByClientCert</url-pattern>

</web-resource-collection>

<auth-constraint>

<role-name>members</role-name>

</auth-constraint>

</security-constraint>

 

<login-config>

<auth-method>CLIENT-CERT</auth-method>

<realm-name>Client Cert Users-only Area</realm-name>

</login-config>

 

 

Please pay attention to the <auth-constraint>. It constraints the allowed users to the role of members. So you also need to add user names into tomcat-users.xml. But what‘s the user name? In other authentication methods, users are given the chance to input their name when accessing the protected resources. In CLLENT-CERT method, there is no chance to let uses do that. Certificate is the only credential user presents. So you should use information contained in certificate as user name. Solely using value of CN field won‘t work. Imagine a situation that there are two Johns belong to different organization unit. How tomcat distinguishes these two guys by the CN ? So the correct value you set in tomcat-users.xml is the DN of the user. Below is an example file.

<?xml version=‘1.0‘ encoding=‘utf-8‘?>

<tomcat-users>

<role rolename="tomcat"/>

<role rolename="members"/>

<role rolename="role1"/>

<user username="tomcat" password="tomcat" roles="tomcat"/>

<user username="role1" password="tomcat" roles="role1"/>

<user username="both" password="tomcat" roles="tomcat,role1,members"/>

<user username="CN=clientbrowser, OU=scn1266, O=scn1266, L=sh, ST=sh, C=cn" password="" roles="members"/>

</tomcat-users>

Remember, only put "clientbrowser" in the username field won‘t work!!

 


The connector configuration for this example is,

<Connector port="8443" maxHttpHeaderSize="8192"

maxThreads="150" minSpareThreads="25" maxSpareThreads="75"

enableLookups="false" disableUploadTimeout="true"

acceptCount="100" scheme="https" secure="true"

clientAuth="true" sslProtocol="TLS"

keystoreFile="/root/tomcat.keystore.jks" keystorePass="changeit"

debug="9"

/>

 


 

One question:

If the client owns more than one certificates how the UA sends the server the proper certificate ?

A quick guessing is the UA may send all certificates that the client owns to the server to let the server choose one among them.

 

 

 

    本站是提供個(gè)人知識(shí)管理的網(wǎng)絡(luò)存儲(chǔ)空間,所有內(nèi)容均由用戶發(fā)布,不代表本站觀點(diǎn)。請(qǐng)注意甄別內(nèi)容中的聯(lián)系方式、誘導(dǎo)購(gòu)買等信息,謹(jǐn)防詐騙。如發(fā)現(xiàn)有害或侵權(quán)內(nèi)容,請(qǐng)點(diǎn)擊一鍵舉報(bào)。
    轉(zhuǎn)藏 分享 獻(xiàn)花(0

    0條評(píng)論

    發(fā)表

    請(qǐng)遵守用戶 評(píng)論公約

    類似文章 更多