This week's giveaway is in the Android forum.
We're giving away four copies of Android Security Essentials Live Lessons and have Godfrey Nolan on-line!
See this thread for details.
The moose likes Websphere and the fly likes Implementing a SAML 2.0 token in customized JAAS login in WebSphere 8.0.0.3 Big Moose Saloon
  Search | Java FAQ | Recent Topics | Flagged Topics | Hot Topics | Zero Replies
Register / Login


Win a copy of Android Security Essentials Live Lessons this week in the Android forum!
JavaRanch » Java Forums » Products » Websphere
Bookmark "Implementing a SAML 2.0 token in customized JAAS login in WebSphere 8.0.0.3" Watch "Implementing a SAML 2.0 token in customized JAAS login in WebSphere 8.0.0.3" New topic
Author

Implementing a SAML 2.0 token in customized JAAS login in WebSphere 8.0.0.3

Marcin Rembisz
Greenhorn

Joined: Feb 11, 2013
Posts: 3
The customer requirement is to introduce SAML 2.0 token to implement
single-sign-on (SSO) using WAS 8.0.0.3. The high level security model/login
process for SSO is the following:

1) User logs in to external customer system

2) External primary JAAS system allows user to access if authorization is successfully

3) WebSphere Application server passes SAML token with username encapsulated to secondary internal JAAS login module

4) Internal JAAS login Filter intercepts a call

5) Custom login module is called and need to extract username from SAML token

6) If the login is known the User is authenticated and access granted to internal system, otherwise access is
denied.

I am wondering if anybody can help with providing information how the
SAML token can be obtain in custom login module (point 5 above) using WAS API, and next
how it can be consumed to retrieve issuing username? Is there any WAS specific API available to obtain the SAML token?

I have inspected the code samples in section "Sample code of generating
SAMLToken from SAML XMLStructure or InputStream " provide on the
following page:

http://pic.dhe.ibm.com/infocenter/wasinfo/v7r0/index.jsp?topic=%2Fcom.
ibm.websphere.javadoc.doc%2Fweb%2Fapidocs%2Fcom%2Fibm%2Fwebsphere%
2Fwssecurity%2Fwssapi%2Ftoken%2FSAMLTokenFactory.html

Unfortunately I was not able to find anything similar for token
consumer, could you point me to the right online resources if any, please?
 
I agree. Here's the link: http://aspose.com/file-tools
 
subject: Implementing a SAML 2.0 token in customized JAAS login in WebSphere 8.0.0.3
 
Similar Threads
Migrating JAAS from JBoss to Websphere 6.1
JAAS LoginModule Registration under WebSphere
Implementing a SAML 2.0 token in customized JAAS login in WebSphere 8.0.0.3
JAAS and Websphere
Sharing authentication