Class ConfigFile

java.lang.Object
javax.security.auth.login.Configuration
com.sun.security.auth.login.ConfigFile

public class ConfigFile extends Configuration
This class represents a default implementation for javax.security.auth.login.Configuration.

This object stores the runtime login configuration representation, and is the amalgamation of multiple static login configurations that resides in files. The algorithm for locating the login configuration file(s) and reading their information into this Configuration object is:

  1. Loop through the security properties, login.config.url.1, login.config.url.2, ..., login.config.url.X. Each property value specifies a URL pointing to a login configuration file to be loaded. Read in and load each configuration.
  2. The system property java.security.auth.login.config may also be set to a URL pointing to another login configuration file (which is the case when a user uses the -D switch at runtime). If this property is defined, and its use is allowed by the security property file (the Security property, policy.allowSystemProperty is set to true), also load that login configuration.
  3. If the java.security.auth.login.config property is defined using "==" (rather than "="), then ignore all other specified login configurations and only load this configuration.
  4. If no system or security properties were set, try to read from the file, ${user.home}/.java.login.config, where ${user.home} is the value represented by the "user.home" System property.

The configuration syntax supported by this implementation is exactly that syntax specified in the javax.security.auth.login.Configuration class. In addition, the security property policy.expandProperties can be used to control whether system properties in the configuration file are expanded. If not set, the default value is true which means that properties will be expanded.

See Also: