Is it possible to bypass JAAS authentication and use Authorisation alone?

I have to implement jsp level security (by checking roles) for my JSF application.
Authentications in my appln are done by a different servers. I don't want to disturb that.
I have to implement authorisation alone using JAAS.
Is it possible to bypass JAAS authentication and use Authorisation alone?
I am using custom login module( implements DatabaseLoginModule) for authorisation.
Moreover, after logging in, when a user tries to access a secured jsp page, he should NOT be redirected to login page again. Rather the role checks should be done using existing user credentials stored somewhere. How to invoke the custom DataBaseLoginModule without taking user to login screen?
Any help would be great.
Thanks,
Adhil.J

I have to implement jsp level security (by checking roles) for my JSF application.
Authentications in my appln are done by a different servers. I don't want to disturb that.
I have to implement authorisation alone using JAAS.
Is it possible to bypass JAAS authentication and use Authorisation alone?
I am using custom login module( implements DatabaseLoginModule) for authorisation.
Moreover, after logging in, when a user tries to access a secured jsp page, he should NOT be redirected to login page again. Rather the role checks should be done using existing user credentials stored somewhere. How to invoke the custom DataBaseLoginModule without taking user to login screen?
Any help would be great.
Thanks,
Adhil.J

Similar Messages

  • I have the new iphone and thought I could download Netflix but only found "Netflix Instant's  Best Movies" in the apps. I pay for Netflix monthly. Is it not possible to download it here and use it on the iPhone?

    I have the new iphone and thought I could download Netflix but only found "Netflix Instant's  Best Movies" in the apps. I pay for Netflix monthly. Is it not possible to download it here and use it on the iPhone? Insight appreciated.

    TJBUSMC1973 wrote:
    The iPhone is working, as designed and advertised.  In this case, the user failed to educate themselves properly, either by proper research or asking the right questions, before purchasing the device.
    I understand that the OP failed to do research. But then, I wasn't replying to the OP. I was replying to Chris. I have Verizon. I can talk and use data at the same time with my Droid Maxx. Therefore, the problem is not just with the network. It would be technically possible for an iPhone to do that on Verizon/Sprint if Apple had chosen to use a different chip, such as the kind other phone manufacturers have elected to use.
    Of course, this is probably all irrelevant to the OP's issue. It was merely a point of clarification, especially for those people who are used to being able to use both voice and data at the same time on Verizon. When they switch to an iPhone, they are often surprized at the limitation.
    Best of luck.

  • JAAS-authentication and wls-authorization in a webapp

    Hi,
    I am developing a webapp with jsp, servlets and ejbs.
    My question:
    Is it possible to use JAAS-authentication together with wls-authorization in a
    webapp?
    thanks
    /Chriz

    Hi, Office 365 tenants indeed include an Azure AD tenant in the background and you can implement Single Sign-On against that. The authentication scenario for this case is documented
    here. For the code samples (with steps to create them) see the
    samples' Github repository, especially the
    WebApp-WSFederation-DotNet sample. 
    For the SQL database it's a bit different. Azure SQL Database connection can't be authenticated like this - there's no integration to the "domain" accounts there. So you should create one service account for the SQL connection and use that for
    all the traffic in your web app. If you need authorization for accessing certain data in SQL, you have to implement that on your web application side.

  • Is it possible (without jailbreaking)  to make and USE custom Text tones?

    Anyone?? I figured out custom ringtones with itunes etc (is it me or is itunes on a windows system complicated? lol..probably me....) but can you create and add your own text tones...and also can you have different tones for text, voicemail etc?
    I am new to iPhone (had ipod touches which is very similar) prior to this just had a regular verizon envy touch phone...
    Responses appreciated y'all

    It is possible, I have custom ringtones on mine without jailbreaking using Windows 7 iTunes. Here is how to do it:
    1. Using iTunes, select which song you want to create a ringtone from.
    2. Right click the song, select Get Info, and go to the Options tab.
    3. Choose a start time for where you want your ringtone to start. Add 30 seconds to that number, and input it into the stop time (to make a 30 second ringtone). Select OK.
    4. Create an AAC version by either a) right clicking the song or b) selecting from the Advanced menu at the top of iTunes.
    5. After creating the AAC version, you should be able to see it in iTunes. Right click the song, and select Show in Windows Explorer.
    6. In Windows Explorer, right click the song and hit rename. The file will look something like "Ringtone.m4a"
    7. Change the name to "Ringtone.m4r" (Note: if you don't see the .m4a extension or can't rename it, there is an option in Windows to allow you to rename file extensions)
    8. After renaming, drag the song to your iTunes, and iTunes will automatically create a "Ringtones" folder, and will sync to your phone.
    Enjoy!
    (Don't forget to change back the start/stop times in your original song)

  • DIGEST Authentication and using Cookies

    Hi,
    I am writing applicationw which can connect to http urls and can communicate with them furthur. I am able to get it when there is BASIC LEVEL OF Authentication but not with DIGEST and Cookies.. i read somewhere that java.net package does not support DIGEST. I am very new to this ares and need ur expert help in this..Also please tell me how can i use cookies in my application..
    Any source code will be a great help..
    Thanks,
    Akhil

    just to keep the query on first page..any body any idea or help...
    Akhil

  • Is it possible to have an iPod and use 2 different iTunes accounts on it?

    My son's father is buying him an iPod 4th Gen for Christmas.  I have NO experience with i-products.  I was saying to his father that I want to set up our son (who is 8) his own iTunes account so I can monitor what is downlaoded on his iPod and such.  He tells me that he was going to add him onto his own so that he will be able to share his apps with him.  So, my question is, if dad puts his apps on there, will I still be able to sign my son up for his own account?

    Welcome to the Apple Community.
    No, he should only use one account.

  • Is it possible to split a song and use different chords?

    Hi there, I have the following question. I see that I can choose a chord type for the song (eg C Maj or C Min).
    However, if I want to change this further in the song it changes for the full song.
    How can I include a split in the song in such a way that I can use multiple tone types through the song?
    I now do this through transponing up and down but that is probably not the proper way.
    Thanks,
    Arnoud

    The "Transposition Track" will allow you to transpose selected measures to a new key for all tracks and loops in parallel.  Add the transposition track from the menu bar: Track > Show Transposition Track.
    Then command-click in the track to create contro points and drag the line between the control ppoints up or down to transpose that region of the song.
    For example, to transpose a part of a song by a fifth:
    Or, if you only want to transpose a part of a rhythm track, transpose selected loops in the track for a chord progression.

  • **** Possible to DRAW notes? and using BUS to send out (side)

     First, in matrix mode, it draws one note at a time, in other daws, you can draw more than one note in a sweeping, sort of SINE WAVE if you want, can this be done? The pencil only allows me to draw once per click and wondering if I have to use a different tool or hold down a command, alt key.
     If I have a percussion track and want to add a AUX bus and place a Noise Gate in it and send the percussion track to the AUX track. How is this done. I keep looking but can't find information on.
    Two questions to be answered. Thanks.

    *In the piano roll it's on note per click as you've already discovered - in the Hyper editor you can draw as many notes/velocities as you like by holding down the pencil tool and dragging it although that's not quite what you're looking for
    *To send a track to a Bus/Aux setup a channel send and assign that to a Bus which will automatically get routed to an Aux unless you have created the Bus you're assigning the signal to in your environment beforehand - the track will then play through the Bus/Aux as well as Outputs 1-2, if you set the Bus/Aux to no Output you can use that signal as a Sidechain Input for Gates, Compressors and whatsoever
    or
    *set the output of your percussion track (located in the first slot above your channel fader) to a Bus - the signal will then only play through that Bus/Aux

  • Is it possible to encrypt my device and use a PIN for my lock screen?

    Standard Android seems to allow this, but when I try to encrypt my Note 3 I am only allowed to select a full password (6 characters, at least 1 number).  Is this something Verizon changed, or is it because of something else I have setup on my device (like an account or something)?

        I can clarify jayjanssen! This is a standard feature on the Note 3. The unlock password must contain at least 6 characters, containing at least 1 number. Thank you.
    TominqueBo_VZW
    Follow us on Twitter @VZWSupport

  • JAAS Authorization and Credentials

    Hi,
    I am adapting an access control system to operate as a JAAS authentication and authorization service. There is a lot of doco covering creation of custom authentication but far less on the authorization side. Any pointers welcome.
    My question is: What is the role of a Subject's "credentials" in the authorization scenario?
    From what I can see a Subject's credentials aren't even available to the authorization service under JAAS? When application code calls methods such as SecurityManager.checkPermission() it seems that a Subject's Principals are passed down to the authorization engine (the Policy) but not the Subject's credentials.
    A ProtectionDomain also has an array of Principals rather than credentials.
    I would like to base the access decisions made by the authorization engine (a custom Policy) on a Subject's credentials. Is there a way? I could just use my credential class as a Principal (with some minor changes) but the information in my class does not represent an idenity, it is a "credential"!
    Any tips gratefully received.

    When application code calls methods such as SecurityManager.checkPermission() it seems that a Subject's Principals are passed down to the authorization engine (the Policy) but not the Subject's credentials.The Subject's public credentials are available via Subject.getPublicCredentials if the JAAS login module has set them up. But the Policy shouldn't need them at this stage. The Subject has already been authenticated by the JAAS login module. All the Policy should be is interested in is what this Subject can do. The credentials aren't for that, they are for authenticating his identity. See below for further discussion.
    A ProtectionDomain also has an array of Principals rather than credentials.Again it doesn't need them. Only the JAAS login module needs them.
    I would like to base the access decisions made by the authorization engine (a custom Policy) on a Subject's credentials.You should base it on the Subject itself and its Principals. Specifically the idea is that he has one or more RolePrincipals that name the roles he is allowed to act as in the application.
    So you write a JAAS LoginModule that inspects the credentials, Principal, name etc and adds RolePrincipals to the subject according to what he is now allowed to do. Then your custom Policy just looks for the appopriate Principal in the Subject. If there, OK, if not, bang you're dead.
    From one point of view this is an efficiency measure. From another point of view it is an essential normalization. You could have millions of credential sets that all map to the same role. And you certainly don't want your Policy to be concerned with individual credentials, only with the Roles they map to.

  • Possible to gut a Mac G5 and use it as a pc?

    Hi everyone, I know people ask these types of questions all the time, but I am wondering if it would be possible to gut my G5 and use its hdd, ram, etc. and house a new mobo/cpu in the G5's case? With black friday coming I was thinking about building a PC when I realized I have an old G5 that has a great case and ram-- so, if I could just keep the case and ram and hdd, it would save me a ton of money. Any help would be appreciated. Thank you.

    Hi Dom,
    Yes indeed, it's been done...
    http://www.overclock.net/t/175131/first-case-mod-water-cooled-pc-in-g5-case
    http://build-its.blogspot.com/2011/04/how-to-fit-your-pc-in-power-mac-g5-case.ht ml
    The RAM would depend on which Mobo you get, but the Drive should work.

  • Reducing app size and using memory

    Building with release preference Blank App template will give you a ~200kb .exe, which in running state use ~7mb of memory.
    It has a huge list of external dependencies.
    So, is it possible to reduce app size and using memory?
    Or, how safely unlink from app headers that really didnt used?

    generally speaking  premature optimization is not a good idea.
    Normally those tricks we learned from stone age are picked by tools already.
    (http://stackoverflow.com/questions/6215782/do-unused-functions-get-optimized-out)
    So if you experice performance/optimization issue
    optimization ususally goes with repeated measure -> optimize -> verify
    cycles.

  • Question about loading and using Images.

    I know how to load an image and to draw it onto a canvas etc etc. However my question is to do with the efficiency of loading multiple images (possibly the same image!) and using them together. I have multiple objects, all instances of the same class, which all draw themselves onto a screen in different positions. However they all use the same 3 images (depending on an internal state).
    So if I create 5 of these objects and each object calls to load the same image using something along the lines of:
    url = this.getClass().getResource("MyImage.png");
    normalImage = Toolkit.getDefaultToolkit().getImage(url);Does this mean that in the memory there are 5 exactly the same copies of this image? Or does java do something clever and use one image that they would all reference? I suspect I will have 5 in memory but I wanted to ask about this before going and making an imageManager class where I load all the images and just use getMethods in that when drawing. I will not be preforming any transforms or anything on any of the images so they can all literally be the same image but simply drawn in multiple positions on the one canvas.
    (note: I am using active rendering to draw these images myself and then blit it to the screen ...).

    Use ImageIO rather than Toolkit--with Toolkit you need to use a MediaTracker to ensure you have your image loaded before you try to use it.
    If you load an image and then do this:
    MyImage1 = MyImage;
    MyImage2 = MyImage;
    MyImage3 = MyImage;
    There are 4 references to the Image in MyImage. If you don't specifically use a method that gives you a new Image, usually, you are getting a refrence to an image already loaded in memory.

  • Underclocking CPU and using only AC with battery attached

    Is it possible to underclock the CPU and use only AC but with the battery attached to the MBP? If the magsafe connector is unplugged the MBP can switch instantly to use the battery.
    There are many times when an underclocked MBP is enough, like when browsing the web, writting and listening to music. But using only AC with no battery is risking losing information.
    And, if it's possible it can even be an option in the menubar (along with turning off-on WiFi and bluetooth). This way, if more power is needed (ie: running Corel's Painter X), it's a matter of just click underclocking-off.

    A question remains: Why do you want to do this?
    Do you want to maximise the life of your battery?
    Do you want to develop sophisticated software that cares about power usage?
    Do you care about the planet and want to minimise your ecological footprint?
    As far as "an AC adapter that takes the place of the battery and can power the MBP with enough energy" - it is supplied with your computer and is the common or garden variety 85W powerbrick. Furthermore, when the AC is connected "the battery will never be used when not necessary" (only if the power demands are sufficiently high that the power adapter can't supply all the power required) - just as you desire.
    Just to make it clear - when the AC is connected the computer draws its power from the AC first, regardless of whether the battery is in place or not.
    I think you will achieve what you want by using the MBP normally, as designed, and not doing anything special. I think it is designed to do exactly what you seem to want.

  • 802.1x port authentication and Windows Radius, possible?

    Hello,
    I'm just testing at the moment before implementing on our netowrk, but has anyone implemented 802.1x port authentication on there Cisco switch and used a Windows IAS server?  See out users are all all on a Windows domain and I want to authenticate using their active directory credentials.  I think I am fine with the switch config, but it is the Windows IAS/Raduis server.  I have added the switch IP's and secret, but I need to create a policy to accept the domain users and need help.
    Thanks

    Andy:
    Yes of course you can use whatever radius server as a AAA server for 802.1x authentication on the switches. NPS, IAS, ACS, Open RADIUS ....etc.
    If you have problem with configuring the IAS then I would suggest that you post your quesiton in a microsoft forum and not here. They would be able to better assist you with your issue. But you can still look somewhere in this forum or in google to help yourself.
    See this link, it could be useful for you:  https://supportforums.cisco.com/thread/2090403
    Regards,
    Amjad
    Rating useful replies is more useful than saying "Thank you"

Maybe you are looking for

  • Shell script for running obiee 11g services in linux

    Hi We have a requirement to create a shell script inorder to run OBIEE 11G services in Linux OS. It would be very helpful and greatly appreciated if any pointer(s)/documentation on this is provided. Thanks

  • Bridge halts on program start

    CS6 (revision number unknown -- it's the latest), 64-bit on Windows 7. Start program, freezes, throws error: "Adobe Bridge CS6 has stopped working and will now stop." Have tried trouble-shooting suggestions to no avail. (Even the ones that make no se

  • HOw to create a console in a GUI??

    Hi, i have redirectioned the java outoup to write in a file, it reacts perfectly to the system.out but when the new outpot becomes anything else as a printf nothing happens. Anyone knows if it could be that the console is not "flusing" the messages.

  • SAP BPC DOORS SHEET MIS TEMPLATE IMPLEMENTATION

    Hi ALL, In my first Input Template I got the data for individual one.like... Particular -Sales group,  Region, Product we get value. Whereas in my Second MIS Template I need data for the sum of all data from first Template and result for one GL Accou

  • How are these cinebench results on 2010 MBP

    i am trying to do a little digging into how my MBP is performing and i am wondering if anyone can help me read these cinebench results and/or has any advice about this. this is a new thing for me but i would like to run this machine through a number