General question. Server admin setup SPNEGO. The LTPA bullet is marked under Global Security in admin console. My understanding is that SPNEGO captures username from an initial sign-on (ie network). Later, if user goes to an app's URL, few of the many things happening is SPNEGO is going through user's ldap groups (admin console-securtity roles) trying to find group that is tied to app's role names. If match is found, user authorized and can go directly into app without having to use login form to enter credentials. But have problem trying to implement this. Checking HttpServletRequest - getUserPrincipal().getName() and getRemoteUser() at front end of app are coming up null. If SPNEGO is in fact setup correctly, should a null ever be found?
Using SPNEGO and LTPA in WebSphere
741 Views Asked by willish001 At
1
There are 1 best solutions below
Related Questions in SERVLETS
- Redirect inside java interceptor
- Which Should i use for date,time,email in servlet?
- Importing a downloaded JAR file into a Servlet
- Execute RequestDispatcher after 5 seconds
- What's the difference between a ServletHandler and a ServletContextHandler in Jetty?
- How to call servlet file from html
- Requested Resource is not available error
- Struts exclude pattern with spring
- How can I get a custom header from the client in Tomcat?
- How to print Jasper reports from servlets?
- The type javax.servlet.ServletContext and javax.servlet.ServletException cannot be resolved
- ServletContext Attribute : Thread Safety test not working
- Servlet ClassNotFoundException when present in a package ... Why?
- How to create a PDF with iText+XMLWorker from servlet using custom font?
- Starting a ScheduledExecutorService from a servlet with a set of parameters
Related Questions in WEBSPHERE
- Websphere 8.5.5 - shared session context not working
- unable to deploy restful application liberty profile 8.2
- Using Cobertura for Junit testing webapp deployed on WebSphere Liberty Profile
- Combining custom application authentication with JAVA EE security. Possible?
- WAS 8.5 Admin console - Give only access to Deployment
- How do I change callerPrincipal from EJB timer?
- Eclipse Scout RAP UI deployment in Websphere
- com.ibm.wsspi.http.channel.exception.WriteBeyondContentLengthException
- Apache axis2/axiom NoSuchMethodError
- Install wasJmsClient-2.0 feature in Liberty Profile 8.5.5.2
- Not able to start MDB listner
- Why would a class be unable to be cast to an interface it implements?
- JProfiler not able to detect WebSphere JVM
- How to control nodes if DMGR is down in Websphere environment
- Websphere maven dependencies
Related Questions in WEBSPHERE-8
- Combining custom application authentication with JAVA EE security. Possible?
- Precedence of EJB Deployment Descriptors
- How to control nodes if DMGR is down in Websphere environment
- Caused by: javax.ws.rs.NotFoundException
- Websphere maven dependencies
- Alternative to Apache Wink JSONObject/JSONException
- JProfiler Remote Application Integration in web sphere 8.5
- Remove local WebSphere user using script
- Reading configuration file from deployed application with wsadmin scripting
- Websphere 8.5.5.2 server not starting when using IBM SDK 1.7.1_64
- Getting Partial Start message after starting the application
- How to set JMSExpirationTime on MQ Response message for SOAP/JMS based web service?
- Configure JAX-WS web-service over HTTPS in WAS at application level
- get sca module bindings in EAR before deploying
- how to access Web sphere default messaging provide queues using HermesJMS?
Related Questions in SPNEGO
- Implementing SSO in Apache, Jetty or Java Web Service
- Alternative for NegotiationAuthenticator class from JBoss EAP 6 in WildFly 10.1?
- Tomcat Kerberos Spnego authorization not working
- Running SPNEGO Kerberos in parallel with username/password authentication
- java.lang.ClassNotFoundException: org.jboss.security.negotiation.NegotiationAuthenticator
- SPNEGO with Java prompting password many times
- How does SPN with Kerberos works
- Kerberos/SPNEGO authentication through Apache to Cherrypy
- curl on Windows: "GSSException: Defective token detected (Mechanism level: GSSHeader did not find the right tag)"
- Any code examples of SpnegoContextToken with Java client?
- Java SSO using SPNEGO
- WCF Interoperability Kerberos SPNego Enabled Web Service
- authenticate user on server side for Swing clients using kerberos/spnego
- how to pass kerberos ticket to jboss server (5.1.0 AS) from swing client
- Spnego keytab authentication in Tomcat on Windows Server fails
Related Questions in LTPA
- Worklight antXSFRealm login failure after authenticating against Data Power
- Does LTPA token expiration prevent sending of SOAP response to standalone application
- IBM DataPower LTPA
- access LTPA token outside of WebSphere context
- Generate a LTPA2 token from SSO Login in a NodeJS Application
- LTPA Token in Tomcat (Spring security)
- LTPA2 Token Issues in WebSphere WAS 9(Liberty) Post-Migration, Only Resolved by Docker Restart, Not by Automated Deployment
- Passing on LPTA token on webservices call isn't working
- How to use the information in an LTPA token
- Can I obtain an LTPA token from WebSphere Trust Association Interceptor?
- How to resolve Websphere web application login delay due to LTPA token expiration?
- The LTPA token that is used to login is invalid - Maximo Rest API
- Authenticate to website in Javascript to access back-end
- Generate LTPAToken 2 in custom Web Application
- From SAML to LTPA2 Token for IBM BPM 8.5.6
Trending Questions
- UIImageView Frame Doesn't Reflect Constraints
- Is it possible to use adb commands to click on a view by finding its ID?
- How to create a new web character symbol recognizable by html/javascript?
- Why isn't my CSS3 animation smooth in Google Chrome (but very smooth on other browsers)?
- Heap Gives Page Fault
- Connect ffmpeg to Visual Studio 2008
- Both Object- and ValueAnimator jumps when Duration is set above API LvL 24
- How to avoid default initialization of objects in std::vector?
- second argument of the command line arguments in a format other than char** argv or char* argv[]
- How to improve efficiency of algorithm which generates next lexicographic permutation?
- Navigating to the another actvity app getting crash in android
- How to read the particular message format in android and store in sqlite database?
- Resetting inventory status after order is cancelled
- Efficiently compute powers of X in SSE/AVX
- Insert into an external database using ajax and php : POST 500 (Internal Server Error)
Popular Questions
- How do I undo the most recent local commits in Git?
- How can I remove a specific item from an array in JavaScript?
- How do I delete a Git branch locally and remotely?
- Find all files containing a specific text (string) on Linux?
- How do I revert a Git repository to a previous commit?
- How do I create an HTML button that acts like a link?
- How do I check out a remote Git branch?
- How do I force "git pull" to overwrite local files?
- How do I list all files of a directory?
- How to check whether a string contains a substring in JavaScript?
- How do I redirect to another webpage?
- How can I iterate over rows in a Pandas DataFrame?
- How do I convert a String to an int in Java?
- Does Python have a string 'contains' substring method?
- How do I check if a string contains a specific word?
You are confusing a few things. SPNEGO is a mechanism to pass user authenticated in the Kerberos realm to the given service without need to pass user password. It has nothing to do with authorization - this part is done by WebSphere security service based on the id retrieved from the request (in short).
Nullusername usually is effect of not enabling Application Security in the server or not protecting application with Java EE security (security constraints defined in theweb.xml).For some basic information about SPNEGO in WebSphere, check the following page Single sign-on for HTTP requests using SPNEGO web authentication