Integrating Digital Signatures into J2EE Web App

I have a requirement to add digital signature functionality to a J2EE web application. Our customers would like to press a �sign� button on a web page, be prompted to connect their hardware security token (e.g. USB device or smart card), and the signatures stored inside our system for later verification (e.g. in court).
The main issue I can see is that when using hardware-based tokens the private key can never leave the device, so the device itself does the signing. Whereas our J2EE Web Application has all the code on the app server tier, and the data is located on the database (and in our architecture cannot be exported to client PCs for security reasons).
Does anyone know of any solutions to this kind of requirement? Any vendor toolkits that allow this? From what I�ve read from researching this subject the pieces are all there but most web-based security solutions only implement application login authentication of one sort or another.

Hi Tony,
As of DIAdem 2012 there is no product feature that makes it easier to create a web front end to DIAdem.  You can host DIAdem with a terminal services approach such as Citrix, which will give you all of DIAdem's functionality in a web GUI.  You can also host DIAdem on a cloud server if that's where your data is.
On final option is that LabVIEW offers a user programmable web server which can make calls to DIAdem via ActiveX.
Brad Turpin
DIAdem Product Support Engineer
National Instruments

Similar Messages

  • GetAccess SSO and WebLogic J2EE Web app

    I have a J2EE web app (servlets/JSPs) running in WLS5.1sp8. I want to use standard
    J2EE declarative security to protect the application and a WLS custom security
    realm to provide authorisation.
    However, I need to use the Entrust getAccess single sign-on infrastructure to
    do the initial user authentication. I was hoping there might be some way to propogate
    the user's getAccess security credentials into the web application so that when
    the user hits a protected web page, they are not prompted to login in again.
    However, Weblogic should call into my custom realm with the getAccess provided
    user name to check that the user has the correct role.
    Anyone have any ideas how/if this is possible?
    Thanks,
    Martin

    That was a good article on how to maintain access levels based on different user roles and i will need it down the lane. Probably, i used a wrong word when i meant 'unauthorized user'.
    Actually, let me rephrase it,
    Here is my issue rephrased,
    1.) My problem is during authentication phase, I want a functionality where a person is redirected to login page by default if he tries to paste URL of some intermediate page of application directly without logging in.
    2.) This would also pop up another question, which would be what is the best practice to maintain a user's info i.e. his login credentials throughout the application (I am just storing his user id along with a flag which says its true.) .
    Right now, the way i do is, in each action after the user logs in, I check for a session attribute which tells if he has logged. Based on this check, I forward to the next page. But, i think its quite redundant and probably not a best practice. Hence, I need some other elegant way of achieving this.

  • Exchange and Office Web Apps Integration - Wrong Url to Outlook Web App port 444

    Hi,
    I'm trying to setup Office Web Apps integration with Exchange 2013.  Office Web Apps are working fine with SharePoint 2013 and the WAC servers are listed as in a healthy state.
    When trying to open an office document from OWA I get the usual "Sorry...we ran into a problem.  Please try again"
    However I have noticed that the URL that OWA is passing WAC is in the format: https://exchangeservername.domain.com:444/owa/[email protected]/wopi/files...
    This is the backend server address! All the internal and external urls for owa, ecp, ews etc are set to https://mail.domain.com and they all seem to be working fine.  Client Access and Mailbox roles are on the same server.
    If I change the url to https://mail.domain.com/owa/[email protected]/wopi/files... then the office file opens correctly in Office Web Apps
    How do I correct the URL that OWA is sending Office Web Apps?  
    Thanks!

    Hi DJL,
    If everything works well except open document via OWA, it seems Exchange server 2013 has been configured correctly.
    Please follow me to check Office Web Apps Server settings and Integration.
    OWAS settings
    1. Certificate:
    Come from a trusted CA, include FQDN of OWAS farm in SAN field.
    Exportable private key.
    Friendly name must be unique within Trusted Root Certificate Authorities store.
    2. Farm:
    New-OfficeWebAppsFarm with following parameters
    -InternalURL is the FQDN of the server that runs OWAS
    -ExternalURL is the FQDN so that OWAS can be access on the Internet
    -CertificateName is the friendly name of the certificate to be used for HTTPS
    3. Explore this URL https://mail.domain.com/hosting/discovery
    If OWAS works well, you can see a WOPI-discovery XML file in web browser.
    Integration
    1. Configure OWAS URL via EMS,
    Set-OrganizationConfig –WACDiscoveryEndpoint https://mail.domain.com/hosting/discovery
    2. WAC stands for Web Access Components.
    Check App Log the 140 and 142 Event IDs for MSExchange OWA.
    142 means the discovery of the OWAS was successful, 141 means something went wrong.
    3. Enable OWAS.
    By default, OWA Virtual Directory is already enable WAC Viewing on both public and private computer.
    Please run "Get-OwaVirtualDirectory | FL *wac* "to check whether both “WacViewingOnPublicComputersEnabled” and “WacViewingOnPrivateComputersEnabled” parameter is True.
    4. Method to collect logs on OWAS.
    Run following command in OWAS powershell prompt:
    Get-OfficeWebAppsFarm | FL *log*
    More details to refer:
    http://www.msexchange.org/articles-tutorials/exchange-server-2013/management-administration/exchange-2013-office-web-apps-server-integration.html
    Disclaimer:
    Microsoft is providing this information as a convenience to you. The sites are not controlled by Microsoft. Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information found there. Please make sure
    that you completely understand the risk before retrieving any suggestions from the above link.
    Thanks
    If you have feedback for TechNet Subscriber Support, contact
    [email protected]
    Mavis Huang
    TechNet Community Support

  • Issue with multiple digital signatures disabling fast web view

    Hello, I'm using acrobat 9.1 pro and have some questions regarding an issue using multiple signatures on a pdf.
    Why am I asking the question below? My job involves preparing pdf's for submission to FDA. The FDA requires, among other things, that electronically submitted docs have fast web view enabled.
    I am currently exploring ways of using digital signatures to sign pdf reports and still make sure they are FDA spec compliant. My issue involves a document that would have multiple signature fields. What I do is create at least two signature fields in the doc and then save and optimize while enabling fast web view. When I sign the first box and save, the file retains the fast web view status. Yet, when I apply and signatures past the first one, the file is subsequently set to fast web view off without any obvious way of turning it back on. I am confused as to why it gets disabled only after the second, and not right after even the first one was signed. And, of course, I would like to know if it is possible to maintain fast web view and how to do it. I'll gladly accept "tinkering under the hood" of the file suggestions if they exist as well.
    Please let me know if anything is unclear or you need further information.
    Thanks for your time and help.
    ~Vlad

    Hi Vlad,
    Michael actual had the correct answer. The purpose of a "Linearized" file (i.e. a file that has been Optimized for Fast Web View) is to get the first page to display as soon as possible so you can start reading without waiting for the rest of the file to download. As an aside, the designated first page doesn't necessarily have to be page 0 (PDF's use a zero based counting system for pages), but usually it is. To quote the PDF specification, "The primary focus of Linearized PDF is optimized viewing of read-only PDF documents. It is intended that the Linearized PDF be generated once and read many times. Incremental update is still permitted, but the resulting PDF is no longer linearized and subsequently is treated as ordinary PDF."
    When you sign a PDF file the first time the Save process is a "full save", that is the entire document is rewritten so there are no more than two %%EOF (end-of-file) markers in it. The first EOF designates which page to show first and the second EOF designates the end of the rest of the file (so the browser knows when to stop downloading). However, when you add a second (or subsequent) signature the file is saved as an "incremental save" and all of the new data is tacked onto the the end of the original file. This is so you can do a rollback to the previous signed version and allows Acrobat/Reader to check the integrity of each signature independent of any other signatures. It's the incremental save that breaks the linearized optimization of the file.
    Steve

  • Importing older Digital Signatures into an Electronic Document Mgmt System

    I have Adobe PDF documents signed with digital signatures in 2002-03 that I need to import into an EMC Documentum repository without invalidating the signatures.  When I try pulling documents into the system, they are seen as "changed or modified" by the authentication software, and the signatures dissappear.  How do I get around this?

    2002-2003 signatures were signed probably with Acrobat 5 or 6. Two questions:
    1. If you open this PDF in Reader XI, does it validate the signatures as valid?
    2. If you import into Documentum PDF signed with the latest Acrobat version (X or XI), does Documentum import then without errors?
    If the answer to question 1 is "no" then there is something wrong with these PDFs.
    I am not familiar with Documentum, so this is just a speculation.
    My guess is that the answers to both questions are "yes". If so, then Documentum does not support the older PDF signature format (which is still in PDF 1.7 specification).
    If the answer to question 1 is "yes" and to question 2 is "no", then perhaps Documentum does not support signed PDFs.
    I am not familiar with Documentum, so this is just a speculation.

  • Digital signature in SharePoint hosted app

    I am creating a sharepoint hosted app where user must use digital signature(loginname, password) before submitting request.
    I am unable to find any machenism to validate user credentials using jquery/javascript.

    Hi,
    Check the blog below:
    Use tasks to maintain your workflow state. Each approval adds a task for the signer. There is a workflow action to handle this for you. When the task is done, it moves to the next step.
    Use the Wait action to have your workflow pause until a change is made. You would have a column for each signer. When the column is filled in, the workflow continues with the email for the next signer.
    Have a workflow that runs for each signing step. The workflow will be kicked off on item change. You will need a column for each signer again. The workflow will examine each column in order to determine what stage it is on and then email the appropriate person.
    http://sharepoint-community.net/forum/topics/multiple-signatures-in-a-document-library-workflow
    Hope this helps

  • How to Verify digital signature in ABAP web dynpro enviroment

    Hi,
    I have few questions regarding, how we can Verify digital signature in ABAP WebDynpro ?
    Do we have class or function modules to verify digital signature on WAS once signed offline or online interactive form is uploaded back?
    can we use function modules in function group SSFG for validating authors signature? Or any other classes or interfaces are available in NetWeaver environment.
    I searched to find any sample for validating signatures in ABAP WebDynpro, however I could not find any thing. Any sample code will be very useful?
    Thanks,
    Nitesh Shelar.

    I Found that Interface IF_FP_PDF_OBJECT can be used to extract signatures from document.
    Thanks,
    Nitesh Shelar.

  • Incorporate pdf into a web app

    I have an asp web app
    everything works great
    details page - gets good here:
    they want to clik on a button in the app to create a .pdf
    from the web site/apps detail page?
    is this possible,, is there a tool/app or command to do this
    with?
    i would like to have a tool that would pull the record's data
    from the db and create the pdf??? wishing?

    In theory you could do this. I think you'd need a component
    like
    www.asppdf.com
    Jules
    http://www.charon.co.uk/charoncart
    Charon Cart 3
    Shopping Cart Extension for Dreamweaver MX/MX 2004

  • Can we integrate credit card readers into a web app?

    Most readers have companies that support them . . .  I was wondering if it's possible to build a web app, through the online store, to utilize the plug in credit card readers for your phone??

    Web apps are not eCommerce and have no public access (outside) API so ignore those.
    You can create 3rd party solutions that read that data and send it to BC via the API and you can source build that if you need to.
    There is nothing in BC directly for what your asking for.

  • Securing a J2EE web app

    Hi, probably the wrong place to put this but i couldn't find anywhere more suitable :-p
    I've got a web app that i've got secured using a JDBC realm, using web.xml configuration etc and all is well. However I want to limit it so that if a user logs in then no-one can log in again with the same credentials until said user has logged out. Is this possible out of the box with JEE5 or do i have to implement something myself to redirect output.
    Regards
    ARB

    Not sure how 'out the box' you want.
    Tomcat has this feature which can be configured by adding username/password paris to an xml file, I realise Tomcat is not part of the JEE5 bundle but it is 'out the box' and you need a server, right?

  • How can i bring digital signature into biztalk.

    Hi All,
    Actually in my project i need to bring the data from sql but inthat data digital signature also there.
    If i add metadata of adapter then how biztalk will pick because it contains the digital signature.
    Regards,
    Raman

    Are you implying that the data in SQL is secured through a certificate (as in encrypted) or merely that Certificate Thumbprint is stored in the database.
    If it is the former (TDE for SQL) then your BizTalk Host Instance would need to have a certificate which you'd configure on the receive location to authenticate and get the data normally.
    If it is the later then you would use the data picked up through the metaadata/schema and read the field to get the signature.
    Regards.

  • Integrate web part page into access web apps

    Hi All,
    Im using SharePoint 2013 online and Office 2013
    I am working on an access project which would allow the user to upload documents to the documents folder in SP from within an Iframe in an access app all in the same SP.
    The idea is that rather than having to move from one IE tab to the other the user can drag and drop the document in the iframe which will be in the pop up. then have a SP document list displaying bellow this iframe to confirm that the file has been
    indeed uploaded. When I load the app I get a "This content cannot be displayed in a frame" my idea is based in a book "Professinal Access 2013 Programming" chapter 10 Inlining a web app in access web app. I have also read that I can have
    a website viewer which can display a website, folder or file but its asking me for the path which I don't know and it doesn't take URLs.
    I have googled and searched this forum but cant seem to get the documents forlder to display in the iframe.
    I hope im clear and you guys can help me resolve this task.
    Thanks

    Hi,
    You may use powershell script in order to copy et move your page to another location.
    Have a look at this :
    https://gallery.technet.microsoft.com/office/Copy-all-SharePoint-Files-0999c53f
    Best regards.

  • Integrating Diadem into a web app. Is this possible?

    I have a development team that manages a data collection engine that is web based and I am looking into trying to integrate Diadem to it.
    I want to understand my options of doing this.
    Thanks,
    Tony

    Hi Tony,
    As of DIAdem 2012 there is no product feature that makes it easier to create a web front end to DIAdem.  You can host DIAdem with a terminal services approach such as Citrix, which will give you all of DIAdem's functionality in a web GUI.  You can also host DIAdem on a cloud server if that's where your data is.
    On final option is that LabVIEW offers a user programmable web server which can make calls to DIAdem via ActiveX.
    Brad Turpin
    DIAdem Product Support Engineer
    National Instruments

  • Login functinality into a web app. How?

    The database to use in my app has several users with different roles.I wan someone to be able to use the j2ee app as a user of the database( some must not have some rights), but when I do the app the beans are generated based on a predefined connection.How can I edit that connection programaticaly so that i obtain the functionality implemented by the database? I noticed that login info is kept in content.xml. Is there a way to deal this file from a bean?
    ps: I couldn't find anything relevant on the web... maybe I don't know what to search...

    You're storing a reference to the session, or the login information, or something, in an instance variable of the servlet or whatever it is that does the logging in.

  • Has anyone incorporated Digital Signature into apex Form

    Adobe has the capability to use CAC PKI certificate to digitally sign elements of a PDF form. I am trying to build a apex form that resembles a PDF form and have a field that will request the users Cert and then populate the apex form with that cert. Has anyone done this before?

    Did you have any update information about this issue? Can you share with me?

Maybe you are looking for

  • Windows 8 64 bit issues with Cisco AnyConnect Secure Mobility Client version 3.1.04072

    I am having an issue with the Cisco AnyConnect Secure Mobility Client version 3.1.04072 on a Windows 8 64 bit laptop. I am able to create the VPN connection but the connection will not allow data to be transferred. Stats from a manual connection: Cis

  • ADF web select one choice list return value

    hi how can i make a choice list that displays a value but return another value and then use it as a parameter in a method for a button my problem is how to return another value to the button thanks

  • IPhoto hangs when trying to set places

    so far iPhoto 09 is a complete bust for me. Among other things iPhoto is unusable if i try to set places. after typing in a location the pinwheel of death comes up and stays. anyone else seeing this? any fixes?

  • Creative Xtremegamer going bad?

    C? so i got the<font face="arial,helvetica,sans-serif" size=""> X-Fi XtremeGamer Fatalty Pro for free some time ago from a friend, it worked well and all but recently i started to notice first the Xfi CMSS 3D function stopped working all together whi

  • Unity Data Store for unity 8

    Guys,   Im installing unity 8.0.3  , but unfortunately stuck at " cisco data store" .When i searched google itsays to install "sql server 2005 sp3" or"sql server express 2005 sp3". I installed express , but unity assistant still shows the result as "