I've implemented com.ibm.ws.security.web.saml.ACSTrustAssociationInterceptor according to this article https://www.ibm.com/developerworks/library/mw-1612-lansche-trs/index.html. And it seems working. Anyone has an example code to populate subject from the TAIResult?
How to populate Subject from the TAIResult?
665 Views Asked by rickcoup At
1
There are 1 best solutions below
Related Questions in WEBSPHERE
- pcap to Avro on Hadoop
- schedule and automate sqoop import/export tasks
- How to diagnose Kafka topics failing globally to be found
- Only 32 bit available in Oracle VM - Hadoop Installation
- Using HDFS with Apache Spark on Amazon EC2
- How to get raw hadoop metrics
- How to output multiple values with the same key in reducer?
- Loading chararray from embedded JSON using Pig
- Oozie Pig action stuck in PREP state and job is in RUNNING state
- InstanceProfile is required for creating cluster - create python function to install module
Related Questions in SINGLE-SIGN-ON
- pcap to Avro on Hadoop
- schedule and automate sqoop import/export tasks
- How to diagnose Kafka topics failing globally to be found
- Only 32 bit available in Oracle VM - Hadoop Installation
- Using HDFS with Apache Spark on Amazon EC2
- How to get raw hadoop metrics
- How to output multiple values with the same key in reducer?
- Loading chararray from embedded JSON using Pig
- Oozie Pig action stuck in PREP state and job is in RUNNING state
- InstanceProfile is required for creating cluster - create python function to install module
Related Questions in SUBJECT
- pcap to Avro on Hadoop
- schedule and automate sqoop import/export tasks
- How to diagnose Kafka topics failing globally to be found
- Only 32 bit available in Oracle VM - Hadoop Installation
- Using HDFS with Apache Spark on Amazon EC2
- How to get raw hadoop metrics
- How to output multiple values with the same key in reducer?
- Loading chararray from embedded JSON using Pig
- Oozie Pig action stuck in PREP state and job is in RUNNING state
- InstanceProfile is required for creating cluster - create python function to install module
Related Questions in PRINCIPLES
- pcap to Avro on Hadoop
- schedule and automate sqoop import/export tasks
- How to diagnose Kafka topics failing globally to be found
- Only 32 bit available in Oracle VM - Hadoop Installation
- Using HDFS with Apache Spark on Amazon EC2
- How to get raw hadoop metrics
- How to output multiple values with the same key in reducer?
- Loading chararray from embedded JSON using Pig
- Oozie Pig action stuck in PREP state and job is in RUNNING state
- InstanceProfile is required for creating cluster - create python function to install module
Trending Questions
- UIImageView Frame Doesn't Reflect Constraints
- Is it possible to use adb commands to click on a view by finding its ID?
- How to create a new web character symbol recognizable by html/javascript?
- Why isn't my CSS3 animation smooth in Google Chrome (but very smooth on other browsers)?
- Heap Gives Page Fault
- Connect ffmpeg to Visual Studio 2008
- Both Object- and ValueAnimator jumps when Duration is set above API LvL 24
- How to avoid default initialization of objects in std::vector?
- second argument of the command line arguments in a format other than char** argv or char* argv[]
- How to improve efficiency of algorithm which generates next lexicographic permutation?
- Navigating to the another actvity app getting crash in android
- How to read the particular message format in android and store in sqlite database?
- Resetting inventory status after order is cancelled
- Efficiently compute powers of X in SSE/AVX
- Insert into an external database using ajax and php : POST 500 (Internal Server Error)
Popular # Hahtags
Popular Questions
- How do I undo the most recent local commits in Git?
- How can I remove a specific item from an array in JavaScript?
- How do I delete a Git branch locally and remotely?
- Find all files containing a specific text (string) on Linux?
- How do I revert a Git repository to a previous commit?
- How do I create an HTML button that acts like a link?
- How do I check out a remote Git branch?
- How do I force "git pull" to overwrite local files?
- How do I list all files of a directory?
- How to check whether a string contains a substring in JavaScript?
- How do I redirect to another webpage?
- How can I iterate over rows in a Pandas DataFrame?
- How do I convert a String to an int in Java?
- Does Python have a string 'contains' substring method?
- How do I check if a string contains a specific word?
The IBM SAML TAI (
com.ibm.ws.security.web.saml.ACSTrustAssociationInterceptoris an IBM-provided Java class. It is an implementation of the WebSphere Trust Association Interceptor framework, and uses SAML specifications for establishing trust without having to write custom Java code.Based on the wording of your question it sounds as if you may have instead followed the link within that article to a much older (but still valid) technical article about the underlying TAI framework. This guide absolutely describes writing custom code that implements an IBM Java interface (
com.ibm.wsspi.security.tai.TrustAssociationInterceptor) with your own trust logic and covers thepublic TAIResult negotiateValidateandEstablishTrust()method you must implement.A little lower in the TAI article is an overview of three static methods in the TAIResult class to help you populate an identity:
You can build a
Subjectin two ways: have WebSphere create one automatically by providing a userid string (and allowing WebSphere to query the user repository) or manually, by programmatically creating one. The manual approach is the most powerful - you can do everything from create an "ephemeral" user on the fly, including group memberships - or you can use other WAS APIs to create a fully populatedSubjectand then modify it - for example to add group membership on the fly (and not in the underlying user repository).There are code samples of each
Subjectapproach in section "TAI Usage" in the definitive guide to WAS authentication and TAI implementation.If you do build your own
Subjector add custom credential objects, make sure the classes are serializable - see the article's section on propagation.Just to provide some sample code, here's a an example from the article that describes completely building a
Subjecton the fly in yournegotiateValidateandEstablishTrust()method:In IBM's SAML TAI you mention, they themselves implement the above to read SAML XML documents of various flavors from the
HttpServletRequestand process them, constructing an ephemeral or registry user identity depending on configuration.Key documentation: