Hi all,

For starters, let me introduce myself. I am Marian Muller and I work as a
Java EE engineer at SERLI. As part of my job, I will dedicate some time to
contributing to TomEE.

I am working on a simpler way to configure authentication in the embedded
ActiveMQ broker. Currently, you can easily start the embedded broker using
just a few lines of xml:


> <Resource id="MyJmsResourceAdapter" type="ActiveMQResourceAdapter">
>      BrokerXmlConfig =  broker:(tcp://someHostName:61616)
>      ServerUrl       =  vm://localhost
>  </Resource>
>


But if you want to add authentication to the broker, you need to write an
ActiveMQ xml configuration file, and - that feels a bit wrong - you need to
add Spring and ActiveMQ libraries in TomEE! (see
http://tomee.apache.org/jms-resources-and-mdb-container.html)

<Resource id="MyJmsResourceAdapter" type="ActiveMQResourceAdapter">
>     BrokerXmlConfig =  xbean:file:conf/activemq.xml
>     ServerUrl       =  tcp://someHostName:61616</Resource>
>
>

I looked up how the ActiveMQ embedded broker is configured and started, and
I think it should be possible to add an option to the resource adapter to
specify basic user/password authentication. Now I am wondering what this
option should look like ? I see at least three possibilities:

a) Specify a list of (username/password/groups) directly in the
ResourceAdapter options (in tomee.xml). This feels a bit tedious, would
clutter the config file and would require to define a specific syntax.
b) Specify the path to a file (xml? properties? ...), containing the list
of (username/password/groups). This would lighten the configuration file
(tomee.xml) by moving away the verbose stuff.
c) Maybe we could reuse the existing user database from
conf/tomcat-users.xml ? This way we only need a single file to configure
all the users.


This is for the simple username/password authentication, which would use
ActiveMQ's SimpleAuthenticationPlugin.

Now maybe a better way to add JMS authentication would be to reuse the
existing Realm, which can be configured by the users. This would probably
require to write a custom ActiveMQ plugin that checks authentication
against the realm. But this would open much more authentication options!
Now, if you don't mind, I could use some pointers on how to reuse this
Realm, and also how to define another realm for JMS authentication (if the
user wants so)?
To me, this feels like a better way to centralize authentication in Tomcat
Realms!

What do you think? How do you see JMS authentication?
Please tell me if I am going the wrong way here.
I could definitely use the community feedback here! :)

Thank you.
--
Marian MULLER
SERLI

Reply via email to