Securing the JMX Console and Web Console
Both the jmx-console and web-console are standard servlet 2.3 deployments and can be secured using J2EE role based security. Both also have a skeleton setup to allow one to easily enable security using username/password/role mappings found in the jmx-console.war and web-console.war deployments in the corresponding WEB-INF/classes users.properties and roles.properties files.
The security setup is based on two pieces, the standard WEB-INF/web.xml servlet URI to role specification, and the WEB-INF/jboss-web.xml specification of the JAAS configuration which defines how authentication and role mapping is performed.
To secure the JMX Console using a username/password file -
- Locate the jmx-console.war directory. This will normally be in server/default/deploy in your JBOSS_HOME directory. (pico jboss/server/default/deploy/ management/console-mgr.sar/web-console.war/WEB-INF/web.xml )
- edit WEB-INF/web.xml and uncomment the security-constraint block
- edit WEB-INF/classes/jmx-console-users.properties or server/default/conf/props/jmx-console-users.properties (version >=4.0.2) and WEB-INF/classes/jmx-console-roles.properties or server/default/conf/props/jmx-console-roles.properties (version >=4.0.2) and change the users and passwords to what you desire. They will need the JBossAdmin role specified in the web.xml file to run the JMX Console.
- edit WEB-INF/jboss-web.xml and uncomment the security-domain block. The security-domain value of jmx-console maps is declared in the login-config.xml JAAS configuration file which defines how authentication and authorization is done.
To secure the JMX Console using your own JAAS domain -
- edit WEB-INF/web.xml as above, uncommenting the security-constraint block. Change the role-name value to be the role in your domain that can access the console
- edit WEB-INF/jboss-web.xml as above, setting the security domain to be the name of your security domain. For example, if your login-config.xml has an application-policy whose name is MyDomain then your JAAS domain java:/jaas/MyDomain
- after making all the changes, redeploy the application. The application can be redeployed by touching the web.xml file or by restarting the server
The process to secure the web console is similar. In the deploy directory, locate management/web-console.war and make the same changes as above to to WEB-INF/web.xml, WEB-INF/jboss-web.xml and the users/groups properties file. The default JAAS domain used by the web-console is java:/jaas/web-console and is defined in login-config.xml in the conf directory. You can use a custom JAAS domain or custimize the existing domain in the same way as with the JMX console. Typically you would just use the same domain (java:/jaas/jmx-console) as the jmx-console so that you have a single user/role mapping to configurue.
If you find as I did with 3.2.5 that I couldn’t log in, another users.properties is most likely being picked up. Change the web-console login-config.xml entry so that that properties files are uniquely named to avoid ambiguity with which resource is picked up. You also would need to rename the web-console properties files. (see http://www.jboss.org/index.html?module=bb&op=viewtopic&t=53346
)
As an extra level of security you may also want to LimitAccessToCertainClients in a particular IP address range.
Enabling authentication to the RMIAdaptor service
Since 3.2.4, the JMX Detached Invoker Service which provides the RMIAdaptor interface into the MBeanServer has supported JAAS authentication of callers.
Note, there is a bug
in the 4.0.x implementation that is fixed in 4.0.5 GA.
To enable this:
- in JBossAS 4.0.x, edit jmx-invoker-service.xml
- in JBossAS 3.2.x, edit jmx-invoker-adaptor-server.sar/META-INF/jboss-service.xml
and uncomment the descriptors section of the invoke operation:
<operation>
<description>The detached invoker entry point</description>
<name>invoke</name>
<parameter>
<description>The method invocation context</description>
<name>invocation</name>
<type>org.jboss.invocation.Invocation</type>
</parameter>
<return-type>java.lang.Object</return-type>
<!-- Uncomment to require authenticated users -->
<descriptors>
<interceptors>
<interceptor code="org.jboss.jmx.connector.invoker.AuthenticationInterceptor"
securityDomain="java:/jaas/jmx-console"/>
</interceptors>
</descriptors>
</operation>
The value of the securityDomain attribute maps to the security domain name found in the conf/login-config.xml definitions the same way as the jboss.xml, jboss-web.xml security-domain elements do. In this case the jmx-console security domain configuration is being used.
courtesy: http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureJBoss
32 Responses.
Following my exploration, millions of people in the world receive the loan from various banks. Therefore, there’s a good chance to get a commercial loan in all countries.
Radio frequency welding of plastics | Best and Free tips on the ……
RF welding is a technology enabling and the basic equipment necessary to affect these joints changed since the inception of this process. Today, as in 1942, ……
Quick and best ways to lose weight safely and naturally online…
Find the best ways to lose weight,Like laxatives,dieting,Make you quick and easy ways to lose weight safely and naturally….
Purchase mp3 music online…
This article award many tips. It is handy….
Very informative post. Thanks for taking the time to share your view with us.
Rapid weight loss plan and diets…
I must say, I enjoy reading your site. Maybe you could let me know how I can subscribing with it ? Also just thought I would tell you I found this site through google….
Buy Soft Toys & Childrens Toy online now!…
Great headline. If your cookie has a bite-sized action and your reader completes the action, I think two things happen. Their self-confidence goes up (which feels good) and their trust in you increases….
The Best Family Vacation Ideas – For Family Vocations…
My favorite trap sheet. Thank you…
Thank you……
Very good, i like you.And say and say ?? It? greatttttttttttt?…..
Healthy diet plan…
goodto see you make postings on this issue, I should bookmark this web site. Just keep up the good job….
Best Medical Insurance – Cheap Health Insurance Quotes…
Excellent, You show exceedinglyprofessionaland presents wellto silent future….
Best mortgage rate today…
Great post.Thanks a lot….
Best Weight Loss and Health Fitness Exercise Tips…
Your website is certainly full of remarkable information and facts and also is actually extremely enjoyable to read through.Properly carried out:)…
Free Games Download – Free Games Online – Free PC Games…
Just started listening to this… sounds great….
Best Family Holiday Travel Vacation Plan…
I will make sure and bookmark this page, I will come back to follow you more….
Unique Wedding Ideas Planning…
excellent post. I will bookmark it! Cheers…
Low Fat & Low Carb Recipes – Healthy Diet Recipes…
I visit your blog practically daily and i like what are you doing with it. Many intresting articles on lots of hot topics and tendencies also, you have skills at writing. I always learn new things with the help of this blog and for that i thank you wit…
Latest Software Reviews, Software Recommendations & Software Comparison…
I added your place of duty to my blog!…
Best Life Insurance Quotes, Rates & Policy…
Impressive publish – I’ve been struggling with this pro around period and it’s impressive to go with this in turn….
Great Photography Tutorials…
Finicky to back your blog, I realize it again on behalf of on the order of a month, right now I give rise to bookmarked it….
Online Fitness Program and Weight Loss Exercise Plan…
This is a really nice blog you got here. The theme is great! Color combination is awesome….
Cheers mate, bom post!
Intriguing post. I have been searching for some good resources for solar panels and discovered your blog. Planning to bookmark this one!…
I REALLY liked your post and blog! It took me a minute bit to find your site…but I bookmarked it. Would you mind if I posted a link back to your post?…
Hi…
I saw this really good post today….
I’ve just started off a blog, the knowledge you give on this site has aided me extremely. Thank you for all your time & work….
Of course, what a great site and informative posts, I will add backlink – bookmark this site? Regards, Reader…
Intriguing post. I have been searching for some good resources for solar panels and discovered your blog. Planning to bookmark this one!…
I REALLY liked your post and blog! It took me a minute bit to find your site…but I bookmarked it. Would you mind if I posted a link back to your post?…
really agreed with what they were saying and thought I would share it with you all…
was surprised by this so thought I would share it with my readers…
Spend some time checking over this info…
what were these guys thinking…
Sometimes you come across someones info taht you just need to share…
Great blog entry, head over and check it out…
Spend some time checking over this info…
what were these guys thinking…
The Best Family Vacation Ideas – For Family Vocations…
I agree with the previous commenter, the article is great….
How sport! Who doesn’t like a puzzle? And, of course, it’s human temperament for equal to hope for to be “bizarre” than the interlude and personalize it with their own artwork. At least, an artistic and artistic being would contemplate that conduct!
Regards, Joshuah