Wow! That is a hell of an answer! :-) Thanks.

OK, so I understand the realms or not a good option.

I think you are right about making this a generic way to configure AMQ
plugins. I will have a look at the whole resource adapters / plugins /
XBean configuration stuff.

About the resource-lookup and the AMQ api to use in
org.apache.openejb.resource.activemq.ActiveMQ5Factory#createBroker, this is
pretty much what I figured.

So yes, to me this makes sense.

--
Marian MULLER
SERLI


On Fri, May 30, 2014 at 11:54 AM, Romain Manni-Bucau <[email protected]>
wrote:

> Hi
>
> great to hear!
>
> About using realm I'm -1 since it has to work with openejb (without tomcat)
> since that's a very current usage.
>
> Now how to impl it: we have to reuse AMQ logic as much as possible. You
> just need to add the authenticator plugin
> in org.apache.openejb.resource.activemq.ActiveMQ5Factory#createBroker. I
> think this task can be more generic and should allow configuration of AMQ
> plugins.
>
> In org.apache.openejb.resource.activemq.ActiveMQ5Factory#createBroker you
> can call on the broker org.apache.activemq.broker.BrokerService#setPlugins.
> So then the question is: how to get plugins?
>
> I'd say: either with openejb services or resources. Let suppose we use
> resources (think it makes sense), I'd expect it in the conf:
>
> <tomee>
>
> <Resource id="ra" type="ActiveMQResourceAdapter">
>     Plugins = plugin1, plugin2...
> </Resource>
>
> <Resource id="plugin1"
> class-name="org.apache.activemq.security.SimpleAuthenticationPlugin">
>    # check XBean org.apache.xbean.propertyeditor.CollectionUtil#toMap for
> the correct syntax or just use a format you think is easier
>    userPasswords = user1=password1\nuser2=password2
> </Resource>
>
> <Resource id="plugin2"
> class-name="org.apache.activemq.security.SimpleAuthenticationPlugin">
>    # check XBean org.apache.xbean.propertyeditor.CollectionUtil#toMap for
> the correct syntax or just use a format you think is easier
>    userPasswords = user1=password1\nuser2=password2
> </Resource>
> </tomee>
>
> So in summary:
>
> 1) add Plugins configuration to ActiveMQResourceAdapter (in class =>
> setPlugins(string) which will split the plugin ids and lookup them as the
> datasource - see end of the mail - + attribute), in service-jar.xml
>
> (container/openejb-core/src/main/resources/META-INF/org.apache.openejb/service-jar.xml)
> as attribute of ActiveMQResourceAdapter (think to default case where no
> plugin are set we don't want to call setPlugins on the broker)
> 2) check syntax we can use with
> XBean org.apache.xbean.propertyeditor.PropertyEditors for plugins
>
>
> Too lookup plugins (using resources) you need this code:
>
>                                 final ContainerSystem containerSystem =
> SystemInstance.get().getComponent(ContainerSystem.class);
>                                 final Context context =
> containerSystem.getJNDIContext();
>                                 final Object obj =
> context.lookup(JndiConstants.OPENEJB_RESOURCE_JNDI_PREFIX + resouceId);
>                                 if (!(obj instanceof
> org.apache.activemq.broker.BrokerPlugin)) {
>                                     throw new
> IllegalArgumentException("Resource with id " + resouceId
>                                                                        + "
> is not an AMQ plugin, but is " + obj.getClass().getName());
>                                 }
>
>
> Does it make sense?
>
>
>
>
>
>
> Romain Manni-Bucau
> Twitter: @rmannibucau
> Blog: http://rmannibucau.wordpress.com/
> LinkedIn: http://fr.linkedin.com/in/rmannibucau
> Github: https://github.com/rmannibucau
>
>
> 2014-05-30 11:35 GMT+02:00 Marian Muller <[email protected]>:
>
> > Hi all,
> >
> > For starters, let me introduce myself. I am Marian Muller and I work as a
> > Java EE engineer at SERLI. As part of my job, I will dedicate some time
> to
> > contributing to TomEE.
> >
> > I am working on a simpler way to configure authentication in the embedded
> > ActiveMQ broker. Currently, you can easily start the embedded broker
> using
> > just a few lines of xml:
> >
> >
> > > <Resource id="MyJmsResourceAdapter" type="ActiveMQResourceAdapter">
> > >      BrokerXmlConfig =  broker:(tcp://someHostName:61616)
> > >      ServerUrl       =  vm://localhost
> > >  </Resource>
> > >
> >
> >
> > But if you want to add authentication to the broker, you need to write an
> > ActiveMQ xml configuration file, and - that feels a bit wrong - you need
> to
> > add Spring and ActiveMQ libraries in TomEE! (see
> > http://tomee.apache.org/jms-resources-and-mdb-container.html)
> >
> > <Resource id="MyJmsResourceAdapter" type="ActiveMQResourceAdapter">
> > >     BrokerXmlConfig =  xbean:file:conf/activemq.xml
> > >     ServerUrl       =  tcp://someHostName:61616</Resource>
> > >
> > >
> >
> > I looked up how the ActiveMQ embedded broker is configured and started,
> and
> > I think it should be possible to add an option to the resource adapter to
> > specify basic user/password authentication. Now I am wondering what this
> > option should look like ? I see at least three possibilities:
> >
> > a) Specify a list of (username/password/groups) directly in the
> > ResourceAdapter options (in tomee.xml). This feels a bit tedious, would
> > clutter the config file and would require to define a specific syntax.
> > b) Specify the path to a file (xml? properties? ...), containing the list
> > of (username/password/groups). This would lighten the configuration file
> > (tomee.xml) by moving away the verbose stuff.
> > c) Maybe we could reuse the existing user database from
> > conf/tomcat-users.xml ? This way we only need a single file to configure
> > all the users.
> >
> >
> > This is for the simple username/password authentication, which would use
> > ActiveMQ's SimpleAuthenticationPlugin.
> >
> > Now maybe a better way to add JMS authentication would be to reuse the
> > existing Realm, which can be configured by the users. This would probably
> > require to write a custom ActiveMQ plugin that checks authentication
> > against the realm. But this would open much more authentication options!
> > Now, if you don't mind, I could use some pointers on how to reuse this
> > Realm, and also how to define another realm for JMS authentication (if
> the
> > user wants so)?
> > To me, this feels like a better way to centralize authentication in
> Tomcat
> > Realms!
> >
> > What do you think? How do you see JMS authentication?
> > Please tell me if I am going the wrong way here.
> > I could definitely use the community feedback here! :)
> >
> > Thank you.
> > --
> > Marian MULLER
> > SERLI
> >
>

Reply via email to