users@glassfish.java.net

RE: request for feature : "automagic" ldap group to j2ee role mapping

From: Wim V <wim_at_pizzastop.be>
Date: Wed, 11 Jun 2008 20:00:01 +0200

Hi Ron,


You just made it to my personal hero of the month!
I asked and discussed this on the opensso mailing list, but no one gave me
this answer. Hence my surprise this is already in place and yet so simple to
configure.

Thank you very much for your prompt answer.

I would like to share this info on the opensso list as well, it that's ok
with you? There are probably some other people looking for this solution.

>but I believe it is also available in Tomcat.
Just for the record, also in JBOSS, websphere, and in acegi security :)
But I just couldn't find it in glassfish, you can imagine my frustration.
Or better, the relief now I know this CAN be done (and so easily).


Thank you very much,


Wim Verreycken

-----Original Message-----
From: glassfish_at_javadesktop.org [mailto:glassfish_at_javadesktop.org]
Sent: woensdag 11 juni 2008 19:54
To: users_at_glassfish.dev.java.net
Subject: Re: request for feature : "automagic" ldap group to j2ee role
mapping

In Glassfish, go to the admin console and open configuration -> security and
then check
the "Default Principal To Role Mapping Enabled" box.

if you have defined a principal-2-role mapping in any of the sun-specific
deployment decriptors of your application, remove the mappings.

redeploy your app, and you should get the behavior you expect (i.e group x
will be mapped to role x)

this feature is not required by the EE platform, but I believe it is also
available in Tomcat.

you can find more details at:

http://blogs.sun.com/monzillo/entry/principal_2_role_mapping_and

Ron
[Message sent by forum member 'monzillo' (monzillo)]

http://forums.java.net/jive/thread.jspa?messageID=279763

---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe_at_glassfish.dev.java.net
For additional commands, e-mail: users-help_at_glassfish.dev.java.net