Advertisement

07.08.2008 at 01:49AM PDT, ID: 23545837
[x]
Attachment Details

How to adjust weblogic.policy for use of custom authentication providers after activating the SecurityManager

Asked by CJ715 in BEA WebLogic Application Server, Miscellaneous Security, Java Application Servers

Tags: Bea, Weblogic, 10, java security manager

Hi,

my company is using a security framework that is integrated into Bea Weblogic via custom authentication and principal providers. The framework does not need the SecurityManager to be activated but for future extentions like JACC this might become necessary. So we turned on the SecurityManager and found that our custom authentication providers can no longer be loaded by the Weblogic server  due to the now enfored policies.

We tried adjusting the policies but the amount of possible codebases and actions in combination with all resources allows for a multitude of configurations. I did end up with a policy file allowing all components to load but it had a lot of AllPermission entries which just gives me the creeps because i cannot think of all possible security holes i might open up that way that should not be there when a SecurityManager is running. On the other hand i have no clue how to figure out if any problems with such an installation are related to side effects due to possibly too strict policies.

What i would be interested in is a list of components that have to have access to the classes of custom authentication and principal providers (principal provider meaning components like role managers, policy managers, etc.) in order to integrate them properly into Weblogic without any side effects and security holes. At best the list would also include the minimal set of needed permissions and actions for those components.

We filed such a request with Bea support but after a few months of waiting they just told us "do it yourself". But we don't have that much Weblogic know-how to do that in a time efficient way, so i was hoping someone in here would be able to give a solution or at least some pointers.

Thanks,
ChrisStart Free Trial
 
 
[+][-]07.08.2008 at 03:38AM PDT, ID: 21952411

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.09.2008 at 02:08AM PDT, ID: 21961649

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.09.2008 at 08:15AM PDT, ID: 21964565

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.09.2008 at 12:47PM PDT, ID: 21967570

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.09.2008 at 02:56PM PDT, ID: 21968782

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]07.10.2008 at 04:36PM PDT, ID: 21978334

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: BEA WebLogic Application Server, Miscellaneous Security, Java Application Servers
Tags: Bea, Weblogic, 10, java security manager
Sign Up Now!
Solution Provided By: CJ715
Participating Experts: 1
Solution Grade: A
 
 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628