Return-Path: Delivered-To: apmail-tomcat-users-archive@www.apache.org Received: (qmail 75356 invoked from network); 11 Oct 2010 06:46:38 -0000 Received: from unknown (HELO mail.apache.org) (140.211.11.3) by 140.211.11.9 with SMTP; 11 Oct 2010 06:46:38 -0000 Received: (qmail 39784 invoked by uid 500); 11 Oct 2010 06:46:34 -0000 Delivered-To: apmail-tomcat-users-archive@tomcat.apache.org Received: (qmail 39163 invoked by uid 500); 11 Oct 2010 06:46:30 -0000 Mailing-List: contact users-help@tomcat.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: "Tomcat Users List" Delivered-To: mailing list users@tomcat.apache.org Received: (qmail 39144 invoked by uid 99); 11 Oct 2010 06:46:29 -0000 Received: from nike.apache.org (HELO nike.apache.org) (192.87.106.230) by apache.org (qpsmtpd/0.29) with ESMTP; Mon, 11 Oct 2010 06:46:29 +0000 X-ASF-Spam-Status: No, hits=-0.0 required=10.0 tests=SPF_PASS X-Spam-Check-By: apache.org Received-SPF: pass (nike.apache.org: domain of i.galic@brainsware.org designates 188.40.115.121 as permitted sender) Received: from [188.40.115.121] (HELO mail.brainsware.org) (188.40.115.121) by apache.org (qpsmtpd/0.29) with ESMTP; Mon, 11 Oct 2010 06:46:21 +0000 Received: from localhost (localhost.localdomain [127.0.0.1]) by mail.brainsware.org (Postfix) with ESMTP id CF8D61DE271; Mon, 11 Oct 2010 06:46:01 +0000 (UTC) X-Virus-Scanned: amavisd-new at brainsware.org Received: from mail.brainsware.org ([127.0.0.1]) by localhost (mail.brainsware.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IWFstSxhFdGS; Mon, 11 Oct 2010 06:45:59 +0000 (UTC) Received: from mail.brainsware.org (mail.brainsware.org [188.40.115.121]) by mail.brainsware.org (Postfix) with ESMTP id EBDF61DE1FB; Mon, 11 Oct 2010 06:45:59 +0000 (UTC) Date: Mon, 11 Oct 2010 06:45:59 +0000 (UTC) From: =?utf-8?Q?Igor_Gali=C4=87?= To: users@tomcat.apache.org, users@archiva.apache.org Message-ID: <119527907.4518.1286779559838.JavaMail.root@iris> In-Reply-To: <1962037463.4516.1286779068701.JavaMail.root@iris> Subject: Kerberos authentication MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-Originating-IP: [91.130.91.52] X-Mailer: Zimbra 6.0.5_GA_2213.DEBIAN5_64 (ZimbraWebClient - FF3.0 (Linux)/6.0.5_GA_2213.DEBIAN5_64) X-Virus-Checked: Checked by ClamAV on apache.org Hello Happy people, I'm cross-posting this to tomcat and archiva. In our company we have a well established Active Directory infrastructure, I'm running an Apache Archiva 1.3.1 installation in Tomcat 6, on Solaris 10= . The OS has been Kerberos enabled and I would very much like to make use of this for Tomcat/Archiva in order to provide secure authenticated access to it. We need to provide secure and scalable authentication. Thus, everything else has been ruled out: * No authentication -- not good, because we need some form of auditing on who uploaded/deployed what (i.e.: who broke it) * SSH/SCP doesn't scale from an administration point of view (i.e.: we'd have to do something. That could be done wrong, forgotten about or any number of things when people have to do mundane tasks) * Basic authentication -- not so good from an admin's point of view, because clear-text passwords are stored in a Developer's settings.xml. Not so good from a developer's point of view, because s/he has to change their password in settings.xml every month or so. (sic) Given the lack of (official) documentation: http://www.google.com/search?hl=3Den&sitesearch=3Dtomcat.apache.org&q=3Dker= beros+OR+krb&aq=3Df&aqi=3D&aql=3D&oq=3D&gs_rfai=3D http://wiki.apache.org/tomcat/FrontPage?action=3Dfullsearch&context=3D180&v= alue=3Dkerberos+krb&fullsearch=3DText http://www.google.at/search?client=3Dopera&rls=3Den&q=3Dsite:archiva.apache= .org+kerberos+OR+krb&sourceid=3Dopera&ie=3Dutf-8&oe=3Dutf-8 http://www.google.com/search?hl=3Den&domains=3Dcwiki.apache.org%2FARCHIVA&s= itesearch=3Dcwiki.apache.org%2FARCHIVA&q=3Dkerberos+OR+krb&sitesearch=3Dcwi= ki.apache.org%2FARCHIVA&aq=3Df&aqi=3D&aql=3D&oq=3D&gs_rfai=3D I was wondering if that's even in remotely in scope of either Project. It seems fairly simple to integrate Tomcat into a Kerberos Infrastructure (although I haven't had the time to do this so far), the question that remains unanswered to me is how to make Archiva profit from such integration. I appreciate any kind of feedback from people who similarily are stuck between a rock and a hard place, and even more so from those who have a sensible solution :) So long, i --=20 Igor Gali=C4=87 Tel: +43 (0) 664 886 22 883 Mail: i.galic@brainsware.org URL: http://brainsware.org/ --------------------------------------------------------------------- To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org For additional commands, e-mail: users-help@tomcat.apache.org