Hi Stephan, This sounds like a useful thing to support in the Servlet adapter.
The Servlet API allows the retrieval of the authentication type: http://java.sun.com/javaee/5/docs/api/javax/servlet/http/HttpServletRequest. html#getAuthType() So, it's just a matter of calling Restlet's Request#setChallengeResponse() with the proper ChallengeScheme constant. Note that we don't have a constant for "FORM" authentication but we could create a new constant specific to the Servlet adapter. Do you want to take a look at it? Best regards, Jerome -----Message d'origine----- De : [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Envoyé : samedi 17 mai 2008 13:27 À : [email protected] Objet : read the used authentication scheme from Servlet etc. Hi Jerome, Bruno told me (thanks for the detailed answer, Bruno) that I need to request the HttpServltRequest to check, which authentication scheme is used. So I reason, that it is not supported by Restlet now. Right? Are there some plans to support this? A solution could be to copy the authentication scheme in the request attributes with a given key. best regards Stephan Bruno Harbulot schrieb: > Hi Stephan, > > If the request was authenticated using a client certificate, the > following will be non-null: > List<X509Certificate> certificates = > (List<X509Certificate>)getRequest().getAttributes().get("org.restlet.https.c lientCertificates"); > > > I believe this should now work with all types of HTTPS connectors in > Restlet, included behind AJP or with a Servlet (if not, please let me > know and/or fill in a bug report). > > I assume the JAX-RS specification follows the Servlet specification > and the ('auth-constraint' configuration element). > However, in principle, client-side SSL authentication and BASIC/DIGEST > (or even FORM) autentication are orthogonal. You could required both > client-certificate authentication and either of BASIC, DIGEST or FORM. > (It's probably not very sensible in practice). > You would also have to configure the server SSL connector to use at > least "wantClientAuthentication" if not "needClientAuthentication". > > I don't really use Restlet with the Servlet connector, so I'm not > sure, but I don't think it's currently possible to check whether FORM > authentication has been used (as a matter of fact, I'm not sure > whether it's possible to check whether BASIC or DIGEST authentication > has been used when using the Servlet connector). To do so, I would > imagine that a call to getRequest().getAuthType (the request here > being an HttpServletRequest) would be required somewhere in > com.noelios.restlet.ext.servlet.ServletCall, or nearby. > > Best wishes, > Bruno. > > Stephan Koops wrote: >> Hi Bruno and all, >> >> JAX-RS has a method in the API, where the application developer could >> request, which authenticaton scheme was used >> (SecurityContext.getAuthenticationScheme(), if someone is interested) >> If the request was authenticated by BASIC, DIGEST, client certificate >> or Servlet form authentication, I have to return a given constant for >> them. >> Check for BASIC and DIGEST is easy, but how can I check, if the >> request was authenticated by SSL client certificate? And how can I >> check, if it was Servlet form authentication? >> >> best regards >> Stephan

