RE: New security implementation
"Bordet, Simone" <[email protected]>
| Newsgroups | gmane.comp.java.mx4j.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi Luis, > If we want to start a connector server with the minimum > rights then the best thing is to just allow the connector > server to authenticate the identities that connect directly > to it, i.e. the authenticated identitites, and let the ones > that can connect indirectly to it, i.e. the delegate > identities, to be controlled by the Subject Delegation > permission required in the authenticated principal grant > clause. This avoids duplicating things in the policy files. > > There´s also a slight semantic difference between your > implementation and my implementation although it does not > compromise the connector server´s security: > > In my implementation the delegate identity can only connect > through the connection opened by the authenticated identity > whereas in your implementation you let the delegate connect > directly to the server. I have made MX4J behave like you suggest. Thanks a lot ! Simon ------------------------------------------------------- This SF.net email is sponsored by: IT Product Guide on ITManagersJournal Use IT products in your business? Tell us what you think of them. Give us Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more http://productguide.itmanagersjournal.com/guidepromo.tmpl