Return-Path: Delivered-To: apmail-geronimo-user-archive@www.apache.org Received: (qmail 60912 invoked from network); 20 Feb 2009 03:20:19 -0000 Received: from hermes.apache.org (HELO mail.apache.org) (140.211.11.2) by minotaur.apache.org with SMTP; 20 Feb 2009 03:20:19 -0000 Received: (qmail 81780 invoked by uid 500); 20 Feb 2009 03:20:17 -0000 Delivered-To: apmail-geronimo-user-archive@geronimo.apache.org Received: (qmail 81755 invoked by uid 500); 20 Feb 2009 03:20:17 -0000 Mailing-List: contact user-help@geronimo.apache.org; run by ezmlm Precedence: bulk list-help: list-unsubscribe: List-Post: Reply-To: user@geronimo.apache.org List-Id: Delivered-To: mailing list user@geronimo.apache.org Received: (qmail 81746 invoked by uid 99); 20 Feb 2009 03:20:17 -0000 Received: from nike.apache.org (HELO nike.apache.org) (192.87.106.230) by apache.org (qpsmtpd/0.29) with ESMTP; Thu, 19 Feb 2009 19:20:17 -0800 X-ASF-Spam-Status: No, hits=2.4 required=10.0 tests=HTML_MESSAGE,SPF_PASS,WHOIS_MYPRIVREG X-Spam-Check-By: apache.org Received-SPF: pass (nike.apache.org: domain of yingtang1983@gmail.com designates 209.85.198.224 as permitted sender) Received: from [209.85.198.224] (HELO rv-out-0506.google.com) (209.85.198.224) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 20 Feb 2009 03:20:08 +0000 Received: by rv-out-0506.google.com with SMTP id b25so762025rvf.55 for ; Thu, 19 Feb 2009 19:19:46 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:in-reply-to:references :date:message-id:subject:from:to:content-type; bh=y5rakqRO0An2JRE2HadQHjYgUgoiLix74VdOjsKTaGo=; b=sj9efhc1VrNzf/C6IwHFw1+95GVQe2oXrNLo3z/65VUhMdJ4Idg8YRW2yIBn7tUimt MHwzxlhoRACdupdPpx3VLfTS0lBeylqiIvLkhTekEWU1DX6zJUVoHtUrq2F9hBqmdzS4 dMVlQZN47eLE+VVE3y9THJNPMqSC+DdyE3FyU= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :content-type; b=SoHmFxKol3rhhB4/tcAGHLpAfxyBXRWeGqHT5AW5nlyOmna8ZZWxGavT4Ounp2bv/E S2xe5CoZid4gxyFzD43pvIGpUIK0wa4xs1xadfpuWwi2jMRd4UF+XKGO/6cZul3OLFz3 IR4J45mLuI4zQuy/dQqUl8JfHUkNO9NrFxlLw= MIME-Version: 1.0 Received: by 10.142.12.14 with SMTP id 14mr163535wfl.21.1235099986734; Thu, 19 Feb 2009 19:19:46 -0800 (PST) In-Reply-To: References: <22093927.post@talk.nabble.com> <25b884430902190117v1f9a0e80g5ae45f90bb64acb6@mail.gmail.com> <22100434.post@talk.nabble.com> Date: Fri, 20 Feb 2009 11:19:46 +0800 Message-ID: <25b884430902191919v112742b2u168266a4429b1a9@mail.gmail.com> Subject: Re: Admin Console Access and Security Realm From: Ying Tang To: user@geronimo.apache.org Content-Type: multipart/alternative; boundary=000e0cd2e2d2f8ad970463511f96 X-Virus-Checked: Checked by ClamAV on apache.org --000e0cd2e2d2f8ad970463511f96 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Hi David, Thanks for clarification. I really misunderstood the question.. Best Regards, Ying Tang 2009/2/20 David Jencks > > On Feb 19, 2009, at 5:31 AM, Michael2 wrote: > > >> Hello Ying: >> >> Thank you for the information. >> >> I am not clear what you said about the SQL database security realm: "the >> SQL >> database security realm is used to authenticate username and password from >> the built-in Derby database". Could you explain more? >> If we cannot use the realm to authenticate Admin Console users, can we use >> it the authenticate application users? >> > > While what Ying said is correct, I don't think it answered your question. > IIUC what you want to do is covered by the instructions here: > http://cwiki.apache.org/GMOxDOC22/basic-hints-on-security-configuration.html > > Note that the admin console is set up to use a security realm named > "geronimo-admin" so you have to set up your SQL security realm with that > name and disable the realm of that name supplied with geronimo (which will > happen when you include the artifact aliases as recommended in the article). > > hope this helps > david jencks > > > >> >> Thanks. >> >> Michael >> >> >> Sophia Tang wrote: >> >>> >>> Hi Michael, >>> >>> As far as I can tell, the SQL database security realm is used to >>> authenticate username and password from the built-in Derby database, not >>> for >>> Geronimo admin console. >>> >>> For changing the username and password for the Administration Console, >>> you >>> can use the *Users and Groups* portlet in the console. >>> >>> Please see this page for more details: >>> http://cwiki.apache.org/GMOxDOC22/changing-the-username-and-password.html >>> >>> Hope this helps. >>> >>> >>> Best Regards, >>> >>> Ying Tang >>> >>> 2009/2/19 Michael2 >>> >>> >>>> I created a new SQL Security Realm, tested and deployed to Geronimo >>>> 2.1.3 >>>> server, but when I reboot the server and try to use the new user name >>>> and >>>> password defined in the new SQL Security Realm to log into the admin >>>> console, it does not work. I have to use the default user name and >>>> password >>>> to get in. >>>> >>>> My question is: can I use the SQL Security Realm for the Admin Console >>>> user >>>> authentication? >>>> >>>> Thanks for your help. >>>> >>>> Michael. >>>> -- >>>> View this message in context: >>>> >>>> http://www.nabble.com/Admin-Console-Access-and-Security-Realm-tp22093927s134p22093927.html >>>> Sent from the Apache Geronimo - Users mailing list archive at >>>> Nabble.com. >>>> >>>> >>>> >>> >>> >> -- >> View this message in context: >> http://www.nabble.com/Admin-Console-Access-and-Security-Realm-tp22093927s134p22100434.html >> Sent from the Apache Geronimo - Users mailing list archive at Nabble.com. >> >> > --000e0cd2e2d2f8ad970463511f96 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Hi David,

   Thanks for clarification.  I really misu= nderstood the question..

Best  Regards,

Ying Tang
2009/2/20 David Jencks <david_jencks@yahoo.com>

On Feb 19, 2009, at 5:31 AM, Michael2 wrote:


Hello Ying:

Thank you for the information.

I am not clear what you said about the SQL database security realm: "t= he SQL
database security realm is used to authenticate username and password from<= br> the built-in Derby database".  Could you explain more?
If we cannot use the realm to authenticate Admin Console users, can we use<= br> it the authenticate application users?

While what Ying said is correct, I don't think it answered your questio= n.  IIUC what you want to do is covered by the instructions here: &nbs= p;http://cwiki.apache.org/GMOxDOC22/basic-h= ints-on-security-configuration.html

Note that the admin console is set up to use a security realm named "g= eronimo-admin" so you have to set up your SQL security realm with that= name and disable the realm of that name supplied with geronimo (which will= happen when you include the artifact aliases as recommended in the article= ).

hope this helps
david jencks




Thanks.

Michael


Sophia Tang wrote:

Hi Michael,

As far as I can tell, the SQL database security realm is used to
authenticate username and password from the built-in Derby database, not for
Geronimo admin console.

For changing the username and password for the Administration Console,
you
can use the *Users and Groups* portlet  in the console.

Please see this page for more details:
http://cwiki.apache.org/GMOxDOC22/changing-the= -username-and-password.html

Hope this helps.


Best Regards,

Ying Tang

2009/2/19 Michael2 <wtistang@yahoo.com>


I created a new SQL Security Realm, tested and deployed to Geronimo 2.1.3 server, but when I reboot the server and try to use the new user name and password defined in the new SQL Security Realm to log into the admin
console, it does not work. I have to use the default user name and
password
to get in.

My question is: can I use the SQL Security Realm for the Admin Console
user
authentication?

Thanks for your help.

Michael.
--
View this message in context:
http://www.nabble.com/Admin-C= onsole-Access-and-Security-Realm-tp22093927s134p22093927.html
Sent from the Apache Geronimo - Users mailing list archive at Nabble.com.




--
View this message in context: http://www.nabble.com/Admin-Console-Access-and-Security-Realm-tp22093927s1= 34p22100434.html
Sent from the Apache Geronimo - Users mailing list archive at Nabble.com.


--000e0cd2e2d2f8ad970463511f96--