JBoss Community

Re: Remoting with SSL and Cipher Suite

created by renz13 in JBoss AS 7 Development - View the full discussion

I don't understand why do you say they are "completely unrelated" (my english is not so good, maybe i've not explain correctly my problem)?

For the moment I'm using security-realm to manage athentication/authorization of my remote ejb client.

I use a database to store login/password and roles and use ssl to secure and identify my server.


Here is a part of my standalone.xml, which is working :


<security-realm name="myRealm">



            <keystore path="server.keystore" relative-to="jboss.server.config.dir" password="pass"/>




        <jaas name="myDomain"/>




<subsystem xmlns="urn:jboss:domain:remoting:1.1">

    <connector name="remoting-connector" socket-binding="remoting" security-realm="AreaFseRealm"/>



<security-domain name="myDomain" cache-type="default">


        <login-module code="Remoting" flag="optional">

            <module-option name="password-stacking" value="useFirstPass"/>


        <login-module code="Database" flag="required">

            <module-option name="dsJndiName" value="java:jboss/datasources/myDS"/>

            <module-option name="principalsQuery" value="SELECT pass FROM user WHERE username=?"/>

            <module-option name="rolesQuery" value="SELECT r.roles, 'Roles' FROM role r INNER JOIN user u USING (id_user) WHERE u.username=?"/>

            <module-option name="password-stacking" value="useFirstPass"/>






What I try to add now is :

- client certificate authentication (with revocation check) : clients certificates are delivered by a CA. I have the CA certificate and I can download CRL => Maybe i've to code my own TrustManager or something else

- use one of this cipher (i'm developping both client and server side) :




     => If it's not possible, how can I know the cipher used by default?


I thought this could be done in the <jsse> element looking at https://docs.jboss.org/author/display/AS71/Security+subsystem+configuration 

Reply to this message by going to Community

Start a new discussion in JBoss AS 7 Development at Community