Hi,

If you're using CXF 2.4 or afterwards, you can configure "ws- security.ut.validator" to your custom validator. Take a look at this excellent blog to get more details.

[1]http://coheigea.blogspot.com/2011/06/custom-token-validation-in-apache-cxf.html
Freeman
On 2012-3-29, at 下午2:22, Mika Tapanainen wrote:

Hello,

I have read and tested the excellent article

http://www.jroller.com/gmazza/entry/cxf_usernametoken_profile

and I'm thinking how to connect to the external authentication system, when
using the class like ServerPasswordCallback?

If I understood correctly the ServerPasswordCallback must have access to the plain text password. I think if I have an external authentication system I can't get the password. The external authentication system gets the username and password and after that it returns true/false depending if the user has
the access to the system.

What is the model if I want to connect to the external authentication system
from the CXF framework?

BR,

Mika


--
View this message in context: 
http://cxf.547215.n5.nabble.com/CXF-and-external-authentication-system-tp5602765p5602765.html
Sent from the cxf-user mailing list archive at Nabble.com.

---------------------------------------------
Freeman Fang

FuseSource
Email:[email protected]
Web: fusesource.com
Twitter: freemanfang
Blog: http://freemanfang.blogspot.com









Reply via email to