43 Configuring Jakarta Authentication Security
Read the Jakarta Authentication specification at https://jakarta.ee/specifications/authentication/.
This chapter includes the following sections:
-
Jakarta Authentication Mechanisms Override WebLogic Server Defaults
-
unresolvable-reference.html#GUID-56C6F342-A592-4201-89B0-5B053ACE6BD6
This section assumes that you are familiar with a basic overview of Jakarta Authentication, as described in Jakarta Authentication Security in Understanding Security for Oracle WebLogic Server.
Jakarta Authentication Mechanisms Override WebLogic Server Defaults
If you configure an Authentication Configuration Provider for a Web application, it is used instead of the WebLogic Server authentication mechanism for that Web Application. The authentication provider from Jakarta Authentication assumes responsibility for authenticating the user credentials and returning a Subject.
You should therefore exercise care when you specify an Authentication Configuration Provider to make sure that it satisfies your security authentication needs.
Prerequisites for Configuring Jakarta Authentication
There are certain prerequisites for configuring Jakarta Authentication in your environment including, how to make your own or third party server authentication module (SAM) or Authentication Configuration Providers available to WebLogic Server.
The Jakarta Authentication programming model is described in the Jakarta Authentication specification (https://jakarta.ee/specifications/authentication/).
A sample SAM implementation is described in Adding Authentication Mechanisms to the Servlet Container in the GlassFish Server Open Source Edition Application Development Guide. Although written from the GlassFish Server perspective, the tips for writing a SAM, and the sample SAM itself, are instructive.
This section includes the following topics:
Server Authentication Module Must Be in Classpath
If you plan to configure a WebLogic Server Authentication Configuration Provider, you must add the jar for your SAM to the system classpath via the startup scripts or the command line used to start the WebLogic Server instance. If you do not do this, WebLogic Server is not able to find the appropriate classes.
Custom Authentication Configuration Providers Must Be in Classpath
If you plan to configure a custom Authentication Configuration Provider, you must add the jar for your custom Authentication Configuration Provider to the system classpath via the startup scripts or the command line used to start the WebLogic Server instance. If you do not do this, WebLogic Server is not able to find the appropriate classes.
Configuring the OPSS Keystore Service for Custom Identity and Trust: Main Steps
You must configure the OPSS Keystore Service before you can use it for custom identity and trust with WebLogic Server. You can perform the OPSS Keystore Service operations using either Fusion Middleware Control or the Keystore Service commands with WLST.
This section demonstrates the Fusion Middleware Control steps, but Managing Keys and Certificates in Securing Applications with Oracle Platform Security Services describes both options.
Perform the following steps to configure an OPSS Keystore Service for custom identity and trust:
-
Launch Fusion Middleware Control.
-
From the WebLogic Domain menu, select Security then Keystore.
-
Create a keystore in the
systemstripe.-
Select the
systemstripe and click Create Keystore.In the Create Keystore page:
-
Name this keystore.
-
Set the protection type to Password.
-
Set the password.
-
Uncheck the Grant Permission check box.
-
Do not specify a code base URL.
-
-
Select the keystore you just created and click Manage.
Enter the password.
-
In the Manage Certificates page, click Generate Keypair to generate a private/public key pair.
In the Generate Keypair page:
-
Specify the alias for the key pair.
-
Specify site-specific information as appropriate.
-
Accept the default RSA key size if appropriate for your environment. The minimum RSA key size is 2048 bits.
-
Specify the password.
-
Click OK.
-
-
You have the option to use this KSS Demo CA-signed key pair as-is, or to obtain a signed certificate from a reputable vendor such as Entrust, Verisign, and so forth.
To obtain the signed certificate from a reputable vendor, select the alias for the key pair and click Generate CSR. After you create a CSR, send it to your CA, which will authenticate the certificate request and create a digital certificate based on the request.
For instructions on how to import the CA-signed certificate, see Importing a Certificate or Trusted Certificate with Fusion Middleware Control in Securing Applications with Oracle Platform Security Services.
-
If you do not use the preconfigured OPSS Keystore Service trust store
kss://system/trust, you must create your own.Note:
Oracle recommends you use the preconfigured OPSS Keystore Service trust store.
To create your own trust store, create another OPSS Keystore Service keystore, and import trusted certificates. For instructions on how to import trusted certificates, see Importing a Certificate or Trusted Certificate with Fusion Middleware Control in Securing Applications with Oracle Platform Security Services.
-
Configure the WebLogic Server instance to use KSS for Custom Identity and Trust, as described in Configure keystores. You specify the fully-qualified path to the keystore as the URI in the form
kss://system/keystore-name. The keystore type is KSS. -
Configure SSL for the WebLogic Server instance, as described in Set Up SSL.
-
Execute the
syncKeyStoresWLST command. See Synchronizing the Local Keystore with the Security Store in Securing Applications with Oracle Platform Security Services -
Restart WebLogic Server.
Configuring Jakarta Authentication for a Domain
You can configure Jakarta Authentication (formerly JASPIC) for a domain using WebLogic Remote Console and WLST.
By default, Jakarta Authentication is enabled for a domain.
If you disable Jakarta Authentication for a domain, then Jakarta Authentication is disabled for all Web applications in that domain, regardless of their configuration.
To configure Jakarta Authentication for a domain:
- In WebLogic Remote Console, open the Edit Tree and go to Environment, then Domain.
- On the Security tab, click Show Advanced Fields.
- Turn on the JASPIC Enabled option.
- Click Save and commit your changes.
- Using WLST, configure Authentication Configuration providers. See Configuring Jakarta Authentication Using WLST.
After you configure Jakarta Authentication properties for the domain, you can specify which Authentication Configuration provider applies to a specific Web application. See Configure Web Applications for JASPIC in Oracle WebLogic Remote Console Online Help.
Configuring Jakarta Authentication Using WLST
You can use WLST to configure Jakarta Authentication for a domain, and perform tasks such as creating a WebLogic Server Authentication Configuration Provider or a custom Authentication Configuration Provider, listing all WebLogic Server and custom Authentication Configuration Providers, enabling and disabling Jakarta Authentication for a domain.
For information about using WLST, see Understanding the WebLogic Scripting Tool.
This section requires you to configure the following MBeans using WLST:
See MBean Reference for Oracle WebLogic Server for additional MBean information.
Creating a WLS Authentication Configuration Provider
Example 43-1 creates a WLS Authentication Configuration Provider, sets the class name of the SAM, and sets a configuration property.
After you run this example, restart WebLogic Server.
Example 43-1 Create a WLS Authentication Configuration Provider
connect('','','t3://host:port')
Please enter your username :
Please enter your password :
...
edit()
startEdit()
cd('SecurityConfiguration')
cd('mydomain')
jaspic = cmo.getJASPIC()
wacp = jaspic.createWLSAuthConfigProvider('wacp')
am = wacp.getAuthModule()
am.setClassName('com.my.auth.module.Classname')
props = Properties()
props.setProperty('property', 'value')
am.setProperties(props)
save()
activate()Creating a Custom Authentication Configuration Provider
Example 43-2 creates a custom Authentication Configuration Provider, sets the class name of this Authentication Configuration Provider, and sets a configuration property.
After you run this example, restart WebLogic Server.
Example 43-2 Create a Custom Authentication Configuration Provider
connect('','','t3://host:port')
Please enter your username :
Please enter your password :
...
edit()
startEdit()
cd('SecurityConfiguration')
cd('mydomain')
jaspic = cmo.getJASPIC()
acp = jaspic.createCustomAuthConfigProvider('cacp')
acp.setClassName('com.my.acp.Classname')
props = Properties()
props.setProperty('property', 'value')
acp.setProperties(props)
save()
activate()Listing All WLS and Custom Authentication Configuration Providers
Example 43-3 shows how to list all Authentication Configuration Providers for a domain.
Example 43-3 List All Authentication Configuration Providers
connect('','','t3://host:port')
Please enter your username :
Please enter your password :
...
edit()
startEdit()
cd('SecurityConfiguration')
cd('mydomain')
jaspic = cmo.getJASPIC()
jaspic.getAuthConfigProviders()Enabling Jakarta Authentication for a Domain
Example 43-4 shows how to enable Jakarta Authentication for a domain.
After you run this example, restart WebLogic Server.
Example 43-4 Enable Jakarta Authentication for a Domain
connect('','','t3://host:port')
Please enter your username :
Please enter your password :
...
edit()
startEdit()
cd('SecurityConfiguration')
cd('mydomain')
jaspic = cmo.getJASPIC()
jaspic.setEnabled(false)
save()
activate()Disabling Jakarta Authentication for a Domain
Example 43-5 shows how to disable Jakarta Authentication for a domain.
After you run this example, restart WebLogic Server.
Example 43-5 Disable Jakarta Authentication for a Domain
connect('','','t3://host:port')
Please enter your username :
Please enter your password :
...
edit()
startEdit()
cd('SecurityConfiguration')
cd('mydomain')
jaspic = cmo.getJASPIC()
jaspic.setEnabled(false)
save()
activate()