users@glassfish.java.net

Combining SAML and <security-constraint>

From: <glassfish_at_javadesktop.org>
Date: Fri, 19 Mar 2010 05:46:40 PDT

Hello all,

I'm hoping for some pointers. I've got a problem of which I'm sure there is a solution out there, but I can't seem to find it. I've got some web applications where the security constraints are defined in the web.xml (<security-constraint>). This is the way I would like it, so all is fine.

Now I need to switch to an external Identity Provider, which is talking SAML 2.0. I suppose the way to go about it is to write a ServerAuthModule that does the SAML conversation (?), but I can't believe that there is no standard solution for this. Anyone know one (or am I on the wrong track altogether?)

Groeten,

Friso
[Message sent by forum member 'friso']

http://forums.java.net/jive/thread.jspa?messageID=392742