Authentication mechanism

Post by Uks » Wed, 18 Jan 2006 01:14:03

For our INTRANET webservice, we would like to authenticate users or
applications based on a specific ID and password. This will be same for all
users of the web service. what is the best approach to implement this?
Storing the ID and password in config file in encrypted form and authenticate
the callers based on the id and password is enough? or is there a better
solution? do I need WSE at all for this?


Hello All:

Does JBoss support an authentication mechanism similar to Tomcat's
Realms or Resin's Authenticators? In particular, I am looking for a way
to be passed the username and password into a class, which would then
return (perhaps a Boolean) whether that username and password were correct.

The reason I'm asking is that I would like to authenticate against an
XML file like:


or something similar. I don't want to have to edit the web.xml file
because I would like deployment of this application to be something
like: 1) copy the WAR file to the correct location and set up the
server, 2) edit a sample configuration file (with the above
username/password section) to fit the user's needs and 3) use the

Any ideas? Do I really need to mess with JAAS? If so, are there any
tutorials dealing with JAAS and JBoss?

Thank you for your time!

Jonathan M. Rose
President, Farious Net Solutions
Phone: (866)NET-SOLN; Web:
Computer sales and service, Linux deployment and maintenance, low
voltage wiring and Java/database Programming for the northern New
Jersey/New York City area. Call us today!

