Spring 3 and NTLM authentication

前端 未结 3 2003
孤街浪徒
孤街浪徒 2020-12-15 12:17

I am using a spring 3 web application, as Spring 3 doesn\'t support NTLM authentication, what are the other alternatives that can be used along with Spring security? So that

相关标签:
3条回答
  • 2020-12-15 13:08

    Waffle is drop in solution that can be used with springsecurity to achieve this: https://github.com/dblock/waffle

    I've used it myself with for example hybris. They have some examples. Beware of version 1.5 that uses jna3.5 which can cause problems at high load Also beware that you may need to extend negotiatesecurityfilter if our application needs to do authorization(I had to do that, may be fixed in 1.6.

    0 讨论(0)
  • 2020-12-15 13:16

    I have done it one time. Grab it here. It will required to do some small setup at AD level. Feel free to ask questions here or on github.

    0 讨论(0)
  • 2020-12-15 13:16

    The simplest way to solve your problem is the following:

    1) Install Apache Web Server and configure to use NTLM authentication using modntlm

    http://modntlm.sourceforge.net/ (Similar you can use Kerberos authentication using mod_auth_kerb using http://modauthkerb.sourceforge.net/)

    2) Configure mod_jk to your Selvlet container (JBoss or Tomcat) http://tomcat.apache.org/connectors-doc/generic_howto/proxy.html After the successful authentication Apache sends the REMOTE_USER header to the servlet container. The header (according the name) contains a user name of the authenticated user Ensure you configure tomcatAuthentication="false" to allow Apache to allow apache to send the REMOTE_USER header

    3) Implement and configure in Spring Security your own PreAuthenticatedProcessingFilter: http://static.springsource.org/spring-security/site/docs/3.1.x/reference/springsecurity-single.html#d0e6167 It should be very similar to the Request-Header Authentication filter: http://static.springsource.org/spring-security/site/docs/3.1.x/reference/springsecurity-single.html#d0e6295 In addition, you should omit a domain name from the user name. The user name is sent in the REMOTE_USER header after NTLM or Kerberos authentication.

    0 讨论(0)
提交回复
热议问题