<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <br>
    <div class="moz-cite-prefix">On 10/1/12 1:03 PM, Mauro Minella
      wrote:<br>
    </div>
    <blockquote
cite="mid:29E7B8530496AB4089D46F3537AF3A2E267E65@DB3EX14MBXC325.europe.corp.microsoft.com"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html;
        charset=ISO-8859-1">
      <meta name="Generator" content="Microsoft Word 14 (filtered
        medium)">
      <style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";
        color:black;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
code
        {mso-style-priority:99;
        font-family:"Courier New";}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
        {mso-style-priority:34;
        mso-margin-top-alt:auto;
        margin-right:0cm;
        mso-margin-bottom-alt:auto;
        margin-left:0cm;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";
        color:black;}
span.EmailStyle18
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:70.85pt 2.0cm 2.0cm 2.0cm;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
      <div class="WordSection1">
        <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US">Thanks Brent,<o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US">I did one step forward, but I&#8217;m still stuck.
            <o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US">Starting from your suggestion<o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US">--&gt;</span><span lang="EN-US"> you need to
            configure a Tomcat Realm to protect the ECP profile handler
            endpoint (...) and you can reuse the JAAS configuration you
            may have configured for the UsernamePassword LoginHandler,
            but you do need to declare the Realm separately in Tomcat</span><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US">I followed these steps:<o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US">1. I created a link between Java and
            login.config that I&#8217;m successfully using for IDP passive
            authentication, so I modified
            %java_home%\lib\security\java.security as follows (line
            #88):<o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US">--&gt; login.config.url.1=<a class="moz-txt-link-freetext" href="file:C:\Program">file:C:\Program</a> Files
            (x86)\Internet2\Shib2IdP/conf/login.config</span></p>
      </div>
    </blockquote>
    <br>
    <br>
    <br>
    As Scott said, it's probably easier to just do this via a system
    property to the JVM (
    <meta http-equiv="content-type" content="text/html;
      charset=ISO-8859-1">
    java.security.auth.login.config), but adding that java.security
    property is equivalent, I believe.<br>
    <br>
    <br>
    <br>
    <br>
    <blockquote
cite="mid:29E7B8530496AB4089D46F3537AF3A2E267E65@DB3EX14MBXC325.europe.corp.microsoft.com"
      type="cite">
      <div class="WordSection1">
        <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p></o:p></span></p>
        <span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
          lang="EN-US"><o:p></o:p></span>
        <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">&lt;Realm
            className="org.apache.catalina.realm.JAASRealm"
            appName="ShibUserPassAuth"/&gt;</span></p>
      </div>
    </blockquote>
    <br>
    <br>
    I believe you may also need to tell it the class that should be used
    for the user principal.&nbsp; Perhaps if you don't it just defaults to
    the first (and probably only) one present, but you can add it for
    good measure.&nbsp; The Shib UsernamePassword LoginHandler populates that
    with principal:
    <meta http-equiv="content-type" content="text/html;
      charset=ISO-8859-1">
    <meta http-equiv="content-type" content="text/html;
      charset=ISO-8859-1">
    <meta http-equiv="content-type" content="text/html;
      charset=ISO-8859-1">
    edu.internet2.middleware.shibboleth.idp.authn.UsernamePrincipal.&nbsp;
    You do that via the 'userClassNames' attribute on the realm.<br>
    <br>
    <span lang="EN-US"><o:p></o:p></span><br>
    <blockquote
cite="mid:29E7B8530496AB4089D46F3537AF3A2E267E65@DB3EX14MBXC325.europe.corp.microsoft.com"
      type="cite">
      <div class="WordSection1">
        <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <br>
        <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US">*****************<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">ott 01, 2012 6:24:06 PM
            org.apache.catalina.realm.JAASRealm authenticate<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">SEVERE: Unexpected error<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">java.lang.SecurityException:
            Configuration Error:<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; No such file
            or directory<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; at
            com.sun.security.auth.login.ConfigFile.&lt;init&gt;(Unknown
            Source)<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">&nbsp; </span></p>
      </div>
    </blockquote>
    <br>
    <br>
    Well, that error is pretty clear.&nbsp; Whatever you've attempted to
    configure as the JAAS config file (as you said, in java.security via
    login.config.url.1) is not there, or is not readable by the process,
    or something similar.&nbsp; Perhaps it doesn't like the space in the
    path. Also, double-check the valid file: URL syntax in Java for a
    Windows path.&nbsp; I'm not a Windows guy, but I know that the required
    file URL format on Windows often trips people up.<br>
    <br>
    <br>
    <br>
    <br>
    <blockquote
cite="mid:29E7B8530496AB4089D46F3537AF3A2E267E65@DB3EX14MBXC325.europe.corp.microsoft.com"
      type="cite">
      <div class="WordSection1">
        <p class="MsoNormal"><span lang="EN-US"><o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US">*****************<o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US">I guess I&#8217;m not configuring the realm properly
            (for instance, I&#8217;m not setting userClassNames and
            roleClassNames because I did not add additional classes),</span></p>
      </div>
    </blockquote>
    <br>
    No, that error has nothing to do with Tomcat, etc, it's clearly a
    JVM level error from the JAAS framework.<br>
    <br>
    <br>
    <br>
    <br>
    <blockquote
cite="mid:29E7B8530496AB4089D46F3537AF3A2E267E65@DB3EX14MBXC325.europe.corp.microsoft.com"
      type="cite">
      <div class="WordSection1">
        <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"> but I can&#8217;t believe I should write a new realm
            from scratch. Can&#8217;t I simply take the same realm that the
            IDP successfully uses, and put it in server.xml?</span></p>
      </div>
    </blockquote>
    <br>
    <br>
    You are confusing terminology there (JAAS module vs Tomcat realm),
    but either way, no, you don't need to write any Java code to make
    this work.&nbsp; What you have is a simple misconfiguration at this
    point, it's not successfully reading the JAAS config file.<br>
    <br>
  </body>
</html>