grouper-users - [grouper-users] RE: Authentication and authorization to grouper WS
Subject: Grouper Users - Open Discussion List
List archive
- From: "Wessel, Keith" <>
- To: "" <>
- Subject: [grouper-users] RE: Authentication and authorization to grouper WS
- Date: Wed, 5 Apr 2017 21:50:44 +0000
- Accept-language: en-US
- Ironport-phdr: 9a23:7F1vHxy6FTvCSTnXCy+O+j09IxM/srCxBDY+r6Qd2usfIJqq85mqBkHD//Il1AaPBtSFraofwLKJ+4nbGkU4qa6bt34DdJEeHzQksu4x2zIaPcieFEfgJ+TrZSFpVO5LVVti4m3peRMNQJW2aFLduGC94iAPERvjKwV1Ov71GonPhMiryuy+4ZPebgFJiTanfb9/Ihq6oRnTu8ILnYZsN6E9xwfTrHBVYepW32RoJVySnxb4+Mi9+YNo/jpTtfw86cNOSL32cKskQ7NWCjQmKH0169bwtRbfVwuP52ATXXsQnxFVHgXK9hD6XpP2sivnqupw3TSRMMPqQbwoXzmp8qFmQwLqhigaLT406GHZhNJtgqJHrhyvpBJ/zIzVYI6JO/VzZbnScc8GSWdbQspdSzJND4WhZIUPFeoBOuNYopHzq1QOsxS+HhKsC/3ryjNQm3T42LM10+U9EQHG0gArAtUDsHfardrrL6cSSv66zK3TwDXCa/NW3Tb96I7PchAguvGAR6x/ftfMyUQ2EQ7Ok1ueqYvgPzyP1+QNtXCW7+V6VeKolm4nsx9+oiK1ysYikYnEgJ8exFPc9Shh3oo5OdK1RFR/bNOqCpdcqTuWOoluTs4jTGxkojg2xqMctZKmfyUG1I4rywPfZvGJa4SI7AzsWeWNLTp9gX9oea+wihep/kWl1+HwSNO73VhPoyZYktTDq24C2hnS58SZV/Ry5UGs0iuV2Q/J8OFLO0U0mLLbK5E/xr4wkYIesV7dES/ygkr3jLSWelw+9ein9evnZKnmqoOdOoNulgHxLLghmsykAesmKAgOQWmb9vii273450H5QbFKjvk3kqnft5DaJN8bqrSnDABIz4Yv8xe/DzG439QEhXQLMk5JdR2dg4XtNVzCOu70Ae29jli0lTdk3fHGPrnvApXXKXjDla/sfbVz6kFC0woz1s5Q55ZPB7EAJPLzXk7xtNrfDh84KAy42fjoB8hg1o8GQ2KAHreZML/OsV+P/u8vLPOMZIgIuDblNfcl/efijWIimVADZ6mpxoAaaHS5HvR9P0WZemTgjs0AEWcMogoxUvbqiFucXj5PeXq+Rbwz6SwmCNHuMYCWDI+3h6GZ0T3+A4ZbfHtuC1aQHG3uepneHfoAdWjadsB7lSEcWKLkVpQszwqGtQnmxqBhI/aOvCAUqMSw+sJy4riZqhwp7jFwS4y+3mCRTys8ymAXSiQt0aRXoEh5y1GE0LM+jvBFQ48Ar8hVWxs3YMaPh9dxDMr/D1rM
Thanks, Chris and Chad. Between the tidbits from the two of you, we now have things working as needed. Now, on to adventures with the web service! Keith From: Hyzer, Chris [mailto:] Ok, sorry, its not a webapp, it’s a web service. So the client needs to send the authentication with the request, not wait to be prompted. So its difficult to use with a browser. But you could try it with
the grouperClient, which is a java command line program… Thanks Chris From: [mailto:]
On Behalf Of Wessel, Keith Sorry, Chris, guess that’s why one should read the file called README.txt. I see that now. However, after removing it, I don’t get prompted for authentication. So, next question: does setting
ws.security.non-rampart.authentication.class to edu.internet2.middleware.grouper.ws. security.WsGrouperKerberosAuthentication tell the web app to prompt for http basic auth when needed? Or do I now need to configure Apache to protect /services and /servicesRestT
using something like mod_krb? Happy to do the latter if the web app won’t do that part, and I assume that’s what I need to do. I’m just unclear, in that case, what the purpose is of the properties that I set in grouper-ws.properties. Since it’s possible to
set Kerberos realms and KDC settings in there, I assume it can do something with it. Keith . Keith From: Hyzer, Chris []
Yes, remove that role and auth constraints. The web.xml should do not authn/authz if kerb will do it.
J Thanks Chris From: []
On Behalf Of Wessel, Keith Hi, all, I’ve been trying to follow the instructions for setting up my Grouper webservice to do Kerberos authentication against our AD. My goal is to prompt the user for http basic auth against AD Kerberos, and once logged in, only authorize users
in the web service users group within Grouper. I’d like access to the web service to be granted/revoked within Grouper alone rather than having to maintain users in my Tomcat config. I’m trying to avoid container-based authentication but am not opposed to
it if that’s the way to go. I’m going for minimal changes to get this working. It looks like there are several ways to accomplish it, though. At present, I’ve set ws.security.non-rampart.authentication.class in grouper-ws.properties to edu.internet2.middleware.grouper.ws. security.WsGrouperKerberosAuthentication. I’ve tried both setting Kerberos.krb5.conf.location to point to
my krb5.conf and, when that failed, I tried setting Kerberos.realm and Kerberos.kdc.address. I get prompted for authentication when I go to /grouper-ws/services/GrouperService, but it always rejects my authentication. I haven’t removed anything from the shipped web.xml and see some auth constraints in there that point to Tomcat
roles. Do I need to remove that role? Or do I need to somehow use that role? Do I need to change something else? Thanks, Keith |
- [grouper-users] RE: Authentication and authorization to grouper WS, Wessel, Keith, 04/05/2017
Archive powered by MHonArc 2.6.19.