<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <br>
    <div class="moz-cite-prefix">On 10/1/12 9:16 PM, Brent Putman wrote:<br>
    </div>
    <blockquote cite="mid:506A4085.7080109@georgetown.edu" type="cite">
      <meta content="text/html; charset=ISO-8859-1"
        http-equiv="Content-Type">
      <br>
      <br>
      I believe you may also need to tell it the class that should be
      used for the user principal.&nbsp; Perhaps if you don't it just
      defaults to the first (and probably only) one present, but you can
      add it for good measure.&nbsp; The Shib UsernamePassword LoginHandler
      populates that with principal:
      <meta http-equiv="content-type" content="text/html;
        charset=ISO-8859-1">
      <meta http-equiv="content-type" content="text/html;
        charset=ISO-8859-1">
      <meta http-equiv="content-type" content="text/html;
        charset=ISO-8859-1">
      edu.internet2.middleware.shibboleth.idp.authn.UsernamePrincipal.&nbsp;
      You do that via the 'userClassNames' attribute on the realm.<br>
    </blockquote>
    <br>
    Sorry, that's not right.&nbsp; I forgot, the Shib LoginHandler isn't
    running in this case for container managed authN.&nbsp; You can try just
    leaving this out until you get your JAAS config file issue sorted
    out.&nbsp; Should it turn out that you do need to add the user principal
    class names, it's going to be the one populated by the VT LDAP JAAS
    module, and fortunately looks like they have an actual Tomcat Realm
    example<span lang="EN-US"> already:</span><br>
    <br>
    <a class="moz-txt-link-freetext" href="http://code.google.com/p/vt-middleware/wiki/vtldapJAAS#Tomcat_Realm">http://code.google.com/p/vt-middleware/wiki/vtldapJAAS#Tomcat_Realm</a><br>
    <br>
  </body>
</html>