Hi

great to hear!

About using realm I'm -1 since it has to work with openejb (without tomcat)
since that's a very current usage.

Now how to impl it: we have to reuse AMQ logic as much as possible. You
just need to add the authenticator plugin
in org.apache.openejb.resource.activemq.ActiveMQ5Factory#createBroker. I
think this task can be more generic and should allow configuration of AMQ
plugins.

In org.apache.openejb.resource.activemq.ActiveMQ5Factory#createBroker you
can call on the broker org.apache.activemq.broker.BrokerService#setPlugins.
So then the question is: how to get plugins?

I'd say: either with openejb services or resources. Let suppose we use
resources (think it makes sense), I'd expect it in the conf:

<tomee>

<Resource id="ra" type="ActiveMQResourceAdapter">
    Plugins = plugin1, plugin2...
</Resource>

<Resource id="plugin1"
class-name="org.apache.activemq.security.SimpleAuthenticationPlugin">
   # check XBean org.apache.xbean.propertyeditor.CollectionUtil#toMap for
the correct syntax or just use a format you think is easier
   userPasswords = user1=password1\nuser2=password2
</Resource>

<Resource id="plugin2"
class-name="org.apache.activemq.security.SimpleAuthenticationPlugin">
   # check XBean org.apache.xbean.propertyeditor.CollectionUtil#toMap for
the correct syntax or just use a format you think is easier
   userPasswords = user1=password1\nuser2=password2
</Resource>
</tomee>

So in summary:

1) add Plugins configuration to ActiveMQResourceAdapter (in class =>
setPlugins(string) which will split the plugin ids and lookup them as the
datasource - see end of the mail - + attribute), in service-jar.xml
(container/openejb-core/src/main/resources/META-INF/org.apache.openejb/service-jar.xml)
as attribute of ActiveMQResourceAdapter (think to default case where no
plugin are set we don't want to call setPlugins on the broker)
2) check syntax we can use with
XBean org.apache.xbean.propertyeditor.PropertyEditors for plugins


Too lookup plugins (using resources) you need this code:

                                final ContainerSystem containerSystem =
SystemInstance.get().getComponent(ContainerSystem.class);
                                final Context context =
containerSystem.getJNDIContext();
                                final Object obj =
context.lookup(JndiConstants.OPENEJB_RESOURCE_JNDI_PREFIX + resouceId);
                                if (!(obj instanceof
org.apache.activemq.broker.BrokerPlugin)) {
                                    throw new
IllegalArgumentException("Resource with id " + resouceId
                                                                       + "
is not an AMQ plugin, but is " + obj.getClass().getName());
                                }


Does it make sense?






Romain Manni-Bucau
Twitter: @rmannibucau
Blog: http://rmannibucau.wordpress.com/
LinkedIn: http://fr.linkedin.com/in/rmannibucau
Github: https://github.com/rmannibucau


2014-05-30 11:35 GMT+02:00 Marian Muller <[email protected]>:

> Hi all,
>
> For starters, let me introduce myself. I am Marian Muller and I work as a
> Java EE engineer at SERLI. As part of my job, I will dedicate some time to
> contributing to TomEE.
>
> I am working on a simpler way to configure authentication in the embedded
> ActiveMQ broker. Currently, you can easily start the embedded broker using
> just a few lines of xml:
>
>
> > <Resource id="MyJmsResourceAdapter" type="ActiveMQResourceAdapter">
> >      BrokerXmlConfig =  broker:(tcp://someHostName:61616)
> >      ServerUrl       =  vm://localhost
> >  </Resource>
> >
>
>
> But if you want to add authentication to the broker, you need to write an
> ActiveMQ xml configuration file, and - that feels a bit wrong - you need to
> add Spring and ActiveMQ libraries in TomEE! (see
> http://tomee.apache.org/jms-resources-and-mdb-container.html)
>
> <Resource id="MyJmsResourceAdapter" type="ActiveMQResourceAdapter">
> >     BrokerXmlConfig =  xbean:file:conf/activemq.xml
> >     ServerUrl       =  tcp://someHostName:61616</Resource>
> >
> >
>
> I looked up how the ActiveMQ embedded broker is configured and started, and
> I think it should be possible to add an option to the resource adapter to
> specify basic user/password authentication. Now I am wondering what this
> option should look like ? I see at least three possibilities:
>
> a) Specify a list of (username/password/groups) directly in the
> ResourceAdapter options (in tomee.xml). This feels a bit tedious, would
> clutter the config file and would require to define a specific syntax.
> b) Specify the path to a file (xml? properties? ...), containing the list
> of (username/password/groups). This would lighten the configuration file
> (tomee.xml) by moving away the verbose stuff.
> c) Maybe we could reuse the existing user database from
> conf/tomcat-users.xml ? This way we only need a single file to configure
> all the users.
>
>
> This is for the simple username/password authentication, which would use
> ActiveMQ's SimpleAuthenticationPlugin.
>
> Now maybe a better way to add JMS authentication would be to reuse the
> existing Realm, which can be configured by the users. This would probably
> require to write a custom ActiveMQ plugin that checks authentication
> against the realm. But this would open much more authentication options!
> Now, if you don't mind, I could use some pointers on how to reuse this
> Realm, and also how to define another realm for JMS authentication (if the
> user wants so)?
> To me, this feels like a better way to centralize authentication in Tomcat
> Realms!
>
> What do you think? How do you see JMS authentication?
> Please tell me if I am going the wrong way here.
> I could definitely use the community feedback here! :)
>
> Thank you.
> --
> Marian MULLER
> SERLI
>

Reply via email to