Hi Marian,

I have always been of the opinion that the default configuration is the simple way, and more complex scenarios need a more complex solution,
and a really deep understanding of ActiveMQ configuration.

The simple solution is seen as a localhost/vm only solution which never goes outside the box - The clients do not see or access the MQ directly.

The complex solutions starts with your scenario - Clients should have remote access and authenticate (and that is a massive step, not to be taken lightly).

So where to address that?

Romain's plugin idea works, but seems like an awful lot of work to replace something that is in effect already there -
The 'xbean:file:conf/activemq.xml'.

I was also initially annoyed by the whole Spring requirement for a 'simple' XML file, but that's an ActiveMQ issue which we have to live with if we want to configure it. Once you use it there really is no issue. To add all that endless functionality to OpenEJB is really outside the box in my opinion. A few megs of jars isn't really such a big issue.

If you start to dig in to ActiveMQ conf (http://activemq.apache.org/version-5-xml-configuration.html) then you'll understand why they maybe opted for the Spring XBean configuration.

What is your greater picture here? Why do you want to allow remote MQ clients to authenticate?

If we start talking about local application authentication then think 'TomEE cluster', then you're only going to have one ActiveMQ server (standalone, and maybe also a cluster) - Aligning authentication with TomEE is probably not going to work.

A JDBC realm could be a solution - Both servers authenticate can authenticate against it.

But really you'd only need one ActiveMQ user/pw per application.

Andy.

On 30/05/2014 11:35, Marian Muller wrote:
Hi all,

For starters, let me introduce myself. I am Marian Muller and I work as a
Java EE engineer at SERLI. As part of my job, I will dedicate some time to
contributing to TomEE.

I am working on a simpler way to configure authentication in the embedded
ActiveMQ broker. Currently, you can easily start the embedded broker using
just a few lines of xml:


<Resource id="MyJmsResourceAdapter" type="ActiveMQResourceAdapter">
      BrokerXmlConfig =  broker:(tcp://someHostName:61616)
      ServerUrl       =  vm://localhost
  </Resource>


But if you want to add authentication to the broker, you need to write an
ActiveMQ xml configuration file, and - that feels a bit wrong - you need to
add Spring and ActiveMQ libraries in TomEE! (see
http://tomee.apache.org/jms-resources-and-mdb-container.html)

<Resource id="MyJmsResourceAdapter" type="ActiveMQResourceAdapter">
     BrokerXmlConfig =  xbean:file:conf/activemq.xml
     ServerUrl       =  tcp://someHostName:61616</Resource>


I looked up how the ActiveMQ embedded broker is configured and started, and
I think it should be possible to add an option to the resource adapter to
specify basic user/password authentication. Now I am wondering what this
option should look like ? I see at least three possibilities:

a) Specify a list of (username/password/groups) directly in the
ResourceAdapter options (in tomee.xml). This feels a bit tedious, would
clutter the config file and would require to define a specific syntax.
b) Specify the path to a file (xml? properties? ...), containing the list
of (username/password/groups). This would lighten the configuration file
(tomee.xml) by moving away the verbose stuff.
c) Maybe we could reuse the existing user database from
conf/tomcat-users.xml ? This way we only need a single file to configure
all the users.


This is for the simple username/password authentication, which would use
ActiveMQ's SimpleAuthenticationPlugin.

Now maybe a better way to add JMS authentication would be to reuse the
existing Realm, which can be configured by the users. This would probably
require to write a custom ActiveMQ plugin that checks authentication
against the realm. But this would open much more authentication options!
Now, if you don't mind, I could use some pointers on how to reuse this
Realm, and also how to define another realm for JMS authentication (if the
user wants so)?
To me, this feels like a better way to centralize authentication in Tomcat
Realms!

What do you think? How do you see JMS authentication?
Please tell me if I am going the wrong way here.
I could definitely use the community feedback here! :)

Thank you.
--
Marian MULLER
SERLI


--
  Andy Gumbrecht

  http://www.tomitribe.com
  [email protected]
  https://twitter.com/AndyGeeDe

  TomEE treibt Tomitribe! | http://tomee.apache.org

Reply via email to