users@glassfish.java.net

Re: securing glassfish admin console using ldap

From: <glassfish_at_javadesktop.org>
Date: Thu, 12 Feb 2009 10:26:44 PST

Jay,

Glad to know that it has worked for you. I am still unsure of why you had to modify the
granted.policy and sun-web.xml. It should not required. Both the admingui/adminapp
sun-web.xml has asadmin as the group and the domain.xml has admin-realm mapped to
LDAP, so my understanding was if you would just be changing the admin-realm to point
to LDAP (instead of default FILE realm) and it should have worked.

Yes, making the group configurable is something we are thinking of. Kumar -- we need to talk
about it.

Now that the problem has been resolved for you, may I request an FAQ entry from you with
exact instructions on how to do this?
http://wiki.glassfish.java.net/Wiki.jsp?page=GlassFishUserFAQ#section-GlassFishUserFAQ-Security

BTW, you didn't tell me which LDAP you are using. I want to try it out myself.

Regards,
Kedar
[Message sent by forum member 'km' (km)]

http://forums.java.net/jive/thread.jspa?messageID=331628