Skip to content

RCBJ.NET Blog

The Intersection of Identity, Integration, API Management, and Application Security.

  • Contact Information
  • RCBJ.NET – About Us
  • Privacy Policy
  • rcbj.net Conventions
  • Quick Reference
  • Computer Measurements
  • Relevant Links

JBoss and LTPAv2 support

July 3, 2012 RCBJ JBoss, JBoss World, Security, Speaking, Uncategorized

I’ve been at a couple of different client sites where there was a heavy IBM product presence, the use of IBM’s proprietary token format-LTPA2, and the need for a non-IBM technology such as JBoss EAP.  Given the nature of the LTPA2 technology (IBM proprietary protocol), there isn’t any direct support that the JBoss community can provide for LTPA2 tokens.

But, do not give up!  Last week, at JBoss World 2012, I presented a solution to this problem. The exact problem being framed as “How can you build a JAAS Subject inside of a JBoss container from an LTPAToken2 cookie that was past to it by WebSEAL?”  We were exploring how to integrate TAMeb (WebSEAL) with JBoss EAP 6.0.  We showed how this could be done using Tivoli Federated Identity Manager’s (TFIM) Security Token Service (STS) to perform an LTPAv2->SAML2 token transformation via a WS-Trust ISSUE call.

Support for the WS-Trust & SAML2 specifications are provided to JBoss by the PicketLink project.  PicketLink is the Identity Management project for JBoss.  It adds support for a variety of security use cases (including Federated Identity Management) to PicketBox (JBossSX)-the JBoss security subsystem.

PicketLink provides a JAAS Login Module called SAML2STSIssuingLoginModule that uses the WS-Trust client API provided by PicketLink to make WS-Trust ISSUE calls to validate tokens.  This Login Module can be configured to use various inputs (HTTP Header values, cookie values, etc) as input tokens.

We have successfully integrated WebSEAL with JBoss using both LTPA2 tokens and ivcred tokens.

Check out the full presentation from JBoss World if you would like to know more.

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

eapIntegrationjaasJBosslogin moduleltpaltpa2ltpav2SamlSaml2security integrationtamtamebwebsealws-trust

Post navigation

Previous Post:DataPower Access Rental—Maybe DataPower in the Cloud?
Next Post:JBoss/PicketLink WS-Trust Client and Third-Party Security Token Services

Recent Posts

  • What Is Digital Privacy?
  • Of Daffy Bastards And Goofy F*cks In The Land Of The Lost: Integration Anti-Patterns From The Dark Side
  • Data Privacy Laws / Regulations Around The World
  • My NAS Appliance Just Turned Ten Years Old
  • Using Curl With SPNEGO

Archives

  • February 2026
  • December 2025
  • November 2025
  • September 2025
  • September 2024
  • August 2024
  • May 2024
  • February 2021
  • July 2020
  • December 2017
  • November 2017
  • October 2017
  • September 2017
  • July 2017
  • June 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • December 2016
  • October 2016
  • August 2016
  • May 2016
  • April 2016
  • March 2016
  • February 2016
  • December 2012
  • November 2012
  • October 2012
  • September 2012
  • July 2012
  • June 2012
  • May 2012
  • April 2012
  • March 2012
  • February 2012
  • January 2012
  • December 2011
  • October 2011
  • June 2011
  • April 2011
  • September 2010
  • July 2010
  • October 2009
  • August 2009
  • June 2009
  • May 2009
  • April 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • March 2008
  • December 2007
  • October 2007
  • February 2007
  • January 2007
  • November 2006
  • September 2006
  • August 2006

Categories

  • architecture
  • Browser
  • cryptography
  • datapower
  • development
  • diagnostics
  • ha
  • IBM JDK
  • internet
  • J2EE
  • java
  • JBoss
  • JBoss World
  • JEE
  • jvm
  • JVM Internals
  • ldap
  • networking
  • Performance
  • Recommended Reading
  • Security
  • Servlet
  • Servlet
  • soa
  • soa appliance
  • SOAP
  • Speaking
  • Sun JDK
  • Uncategorized
  • VPN
  • web
  • web service
  • Weblogic
  • websphere
  • xml
  • xpath
  • xslt
Log in
WordPress ThemeZee.

Discover more from RCBJ.NET Blog

Subscribe now to keep reading and get access to the full archive.

Continue reading

%d