13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

applicationLoginContext LoginModule CallbackHandler Principal Actioninstantiateloginreads the login_configto find theLoginModuleimplementationsput nameCallbackput passwordCallbackhandle Callbacksget usernameget passwordverify username/passwordadd principalto subjectnewsubject.doASFigure 8-8 JAAS sequence diagramThe step-by-step process is described below:1. The application starts the login process using JAAS.2. The LoginContext is initialized.3. During the login process, executed in the LoginContext, a Principal will beauthenticated using the specified callback handler.4. If the authentication was successful the LoginContext commits the login, thePrincipal gets assigned to the Subject.5. The application gets the Subject from the LoginContext.6. The doAs method attempts a secured operation under the acquired Subject.208 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!