users@glassfish.java.net

Re: About Server side security

From: Miroslav Nachev <miro_at_space-comm.com>
Date: Mon, 21 May 2007 10:00:12 +0300
Dear Imran,

If I am understand you correctly you can read the following links:
http://www.nabble.com/New-SwingX-Login-Dialog-t3751686.html
http://forums.java.net/jive/thread.jspa?threadID=26384
http://forums.java.net/jive/thread.jspa?threadID=26338&tstart=0

Also this additional links can be useful for you also:
http://www.nabble.com/Re:-Dynamic-role-handling-t3477479.html
http://forums.java.net/jive/thread.jspa?messageID=217699
http://www.nabble.com/Re:-Dynamic-role-handling-p10627420.html


Best Regards,
Miroslav Nachev

Imran M Yousuf wrote:
Dear Users,

I am new to EJB 3 and JAAS. My previous experience is with Spring and Acegi. Our organization is developing an ERP solution. So we are thinking about a architecture of EJB 3 (Entities, EAO, and BO) + [Spring (IoC) + NetBeans Platform]; Java EE Container is GlassFish. I have been assigned to find out how the security can be implemented. We want the application to container independent. So can someone please help on how the security of the system could be designed.
I was thinking of, certificate based authentication for clients and db based authentication for users; but I am not sure how to implement that as well. So if someone could shed light on that or even provide a document or sample project link it would be helpful.

Thank you in advance,

--
Imran M Yousuf
Software Engineer
Smart IT Engineering
Dhaka, Bangladesh
Email: imran@smartitengineering.com
Mobile: +880-1711402557