Return-Path: Delivered-To: apmail-tomcat-users-archive@www.apache.org Received: (qmail 30105 invoked from network); 18 Jul 2008 23:32:21 -0000 Received: from hermes.apache.org (HELO mail.apache.org) (140.211.11.2) by minotaur.apache.org with SMTP; 18 Jul 2008 23:32:21 -0000 Received: (qmail 71732 invoked by uid 500); 18 Jul 2008 23:32:09 -0000 Delivered-To: apmail-tomcat-users-archive@tomcat.apache.org Received: (qmail 70985 invoked by uid 500); 18 Jul 2008 23:32:07 -0000 Mailing-List: contact users-help@tomcat.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: "Tomcat Users List" Delivered-To: mailing list users@tomcat.apache.org Received: (qmail 70974 invoked by uid 99); 18 Jul 2008 23:32:07 -0000 Received: from athena.apache.org (HELO athena.apache.org) (140.211.11.136) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 18 Jul 2008 16:32:07 -0700 X-ASF-Spam-Status: No, hits=-0.0 required=10.0 tests=SPF_PASS X-Spam-Check-By: apache.org Received-SPF: pass (athena.apache.org: local policy) Received: from [212.85.38.174] (HELO popeye.combios.es) (212.85.38.174) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 18 Jul 2008 23:31:13 +0000 Received: from [192.168.245.129] (p549EAC78.dip0.t-ipconnect.de [84.158.172.120]) (authenticated bits=0) by popeye.combios.es (8.13.8/8.13.8/Debian-3) with ESMTP id m6INVSYh018705 for ; Sat, 19 Jul 2008 01:31:29 +0200 Message-ID: <488127B6.1060500@ice-sa.com> Date: Sat, 19 Jul 2008 01:31:02 +0200 From: =?ISO-8859-1?Q?Andr=E9_Warnier?= User-Agent: Thunderbird 2.0.0.14 (Windows/20080421) MIME-Version: 1.0 To: Tomcat Users List Subject: Re: Disable password checking for Manager app References: <18537331.post@talk.nabble.com> In-Reply-To: <18537331.post@talk.nabble.com> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 8bit X-Spam-Checker-Version: SpamAssassin 3.2.3 (2007-08-08) on popeye.combios.es X-Virus-Scanned: ClamAV 0.92.1/7750/Fri Jul 18 21:43:59 2008 on popeye.combios.es X-Virus-Status: Clean X-Virus-Checked: Checked by ClamAV on apache.org X-Old-Spam-Status: No, score=-97.9 required=2.5 tests=RCVD_IN_PBL, RCVD_IN_SORBS_DUL,USER_IN_WHITELIST autolearn=no version=3.2.3 dracus wrote: > Greetings, all.... > > > I have a web app server that has Apache in front of Tomcat. Apache is > handling user authentication and security checking (through an experimental > X.509 <-> Kerberos gateway service being developed by others in my group, > but that is neither here nor there), and passes the username (as either > REMOTE_USER or Shib-InetOrgPerson-mail) to Tomcat. To get that to work, we > had to include the 'request.tomcatAuthentication="false"' directive in the > AJP block of server.xml. Unfortunately, this kills the Tomcat manager, as > it will no longer allow us to log into it. We use it extensively to deploy > new versions of our web apps, etc. I have tried putting my authenticated > username into tomcat-users.xml as a user with the manager role, and it still > does not allow me to use the manger, with error "403: Access to the > requested resource has been denied". I check the tomcat-users.xml file, and > it has added a password entry (password="null") to my user define. So what > I want to know is, can I get tomcat to accept the username passed in from > Apache without a password (the only connection allowed into Tomcat is AJP) > so that I can put the users allowed to access the manager app into > tomcat-users.xml, and let Apache do all of the authentication? Any pointers > would be greatly appreciated, thanks in advance. > > JDK 1.6.0 > Tomcat 5.5.23 > mod-jk 1.2.21 > http 2.2.4 RHEL 5 > shibboleth sp 1.3.1 Just to add that I am also interested in the question above, or more generally to learn if there exists a way to pass, from Apache through mod_jk to Tomcat, some form of "Tomcat role" for a user already authenticated by Apache. On the other hand, might it not be possible to modify the section of the web.xml of the manager application, so that instead of requiring a "role = manager", it would instead require a specific authenticated user (which could then be the one passed from Apache) ? Andr� --------------------------------------------------------------------- To start a new topic, e-mail: users@tomcat.apache.org To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org For additional commands, e-mail: users-help@tomcat.apache.org