Class SpnegoHttpURLConnection
This mechanism is an alternative to HTTP Basic Authentication where the
HTTP server does not support Basic Auth but instead has SPNEGO support
(take a look at KerberosSpnegoFilter).
A krb5.conf and a login.conf is required when using this class. Take a look at the spnego.sourceforge.net documentation for an example krb5.conf and login.conf file. Also, you must provide a keytab file, or a username and password, or allowtgtsessionkey.
Example usage (username/password):
public static void main(final String[] args) throws Exception {
System.setProperty("java.security.krb5.conf", "krb5.conf");
System.setProperty("sun.security.krb5.debug", "true");
System.setProperty("java.security.auth.login.config", "login.conf");
SpnegoHttpURLConnection spnego = null;
try {
spnego = new SpnegoHttpURLConnection("spnego-client", "dfelix", "myp@s5");
spnego.connect(new URL("http://medusa:8080/index.jsp"));
System.out.println(spnego.getResponseCode());
} finally {
if (null != spnego) {
spnego.disconnect();
}
}
}
Alternatively, if the server supports HTTP Basic Authentication, this Class is NOT needed and instead you can do something like the following:
public static void main(final String[] args) throws Exception {
final String creds = "dfelix:myp@s5";
final String token = Base64.encode(creds.getBytes());
URL url = new URL("http://medusa:8080/index.jsp");
HttpURLConnection conn = (HttpURLConnection) url.openConnection();
conn.setRequestProperty(Constants.AUTHZ_HEADER
, Constants.BASIC_HEADER + " " + token);
conn.connect();
System.out.println("Response Code:" + conn.getResponseCode());
}
To see a working example and instructions on how to use a keytab, take a look at the creating a client keytab example.
Finally, theSpnegoSOAPConnection class is another example of a class
that uses this class.
- Author:
- Darwin V. Felix
-
Constructor Summary
ConstructorsConstructorDescriptionSpnegoHttpURLConnection(String loginModuleName) Creates an instance where the LoginContext relies on a keytab file being specified by "java.security.auth.login.config" or where LoginContext relies on tgtsessionkey.SpnegoHttpURLConnection(String loginModuleName, String username, String password) Creates an instance where the LoginContext does not require a keytab file.Create an instance where the GSSCredential is specified by the parameter and where the GSSCredential is automatically disposed after use.SpnegoHttpURLConnection(GSSCredential creds, boolean dispose) Create an instance where the GSSCredential is specified by the parameter and whether the GSSCredential should be disposed after use. -
Method Summary
Modifier and TypeMethodDescriptionvoidaddRequestProperty(String key, String value) Adds an HTTP Request property.connect(URL url, ByteArrayOutputStream dooutput) connect(URL url, Proxy proxy, ByteArrayOutputStream output) Opens a communications link to the resource referenced by this URL, if such a connection has not already been established.voidLogout and clear request properties.Returns an error stream that reads from this open connection.Returns an input stream that reads from this open connection.booleanReturns true if GSSContext has been established.voidrequestCredDeleg(boolean requestDelegation) Request that this GSSCredential be allowed for delegation.voidsetRequestMethod(String method) May override the default GET method.voidsetRequestProperty(String key, String value) Sets an HTTP Request property.
-
Constructor Details
-
SpnegoHttpURLConnection
Creates an instance where the LoginContext relies on a keytab file being specified by "java.security.auth.login.config" or where LoginContext relies on tgtsessionkey.- Parameters:
loginModuleName- name of the login module- Throws:
LoginException- if the authentication fails
-
SpnegoHttpURLConnection
Create an instance where the GSSCredential is specified by the parameter and where the GSSCredential is automatically disposed after use.- Parameters:
creds- credentials to use
-
SpnegoHttpURLConnection
Create an instance where the GSSCredential is specified by the parameter and whether the GSSCredential should be disposed after use.- Parameters:
creds- credentials to usedispose- true if GSSCredential should be diposed after use
-
SpnegoHttpURLConnection
public SpnegoHttpURLConnection(String loginModuleName, String username, String password) throws LoginException Creates an instance where the LoginContext does not require a keytab file. However, the "java.security.auth.login.config" property must still be set prior to instantiating this object.- Parameters:
loginModuleName- the name of the login moduleusername- the login id of the userpassword- the password of the user- Throws:
LoginException- if the authentication fails.
-
-
Method Details
-
connect
public HttpURLConnection connect(URL url, ByteArrayOutputStream dooutput) throws GSSException, PrivilegedActionException, IOException -
connect
public HttpURLConnection connect(URL url, Proxy proxy, ByteArrayOutputStream output) throws GSSException, PrivilegedActionException, IOException Opens a communications link to the resource referenced by this URL, if such a connection has not already been established.- Parameters:
url- the URL of the resourceproxy- a possible proxy to use to establish a connection with the resourceoutput- optional message/payload to send to server- Returns:
- an HttpURLConnection object
- Throws:
GSSException- if the SSO negotiation failsPrivilegedActionException- if a disallowed action is performed.IOException- if an IO occurs during the connection- See Also:
-
disconnect
public void disconnect()Logout and clear request properties.- See Also:
-
isContextEstablished
public boolean isContextEstablished()Returns true if GSSContext has been established.- Returns:
- true if GSSContext has been established, false otherwise.
-
addRequestProperty
Adds an HTTP Request property.- Parameters:
key- request property namevalue- request propery value- See Also:
-
setRequestProperty
Sets an HTTP Request property.- Parameters:
key- request property namevalue- request property value- See Also:
-
getErrorStream
Returns an error stream that reads from this open connection.- Returns:
- error stream that reads from this open connection
- See Also:
-
getInputStream
Returns an input stream that reads from this open connection.- Returns:
- input stream that reads from this open connection
- Throws:
IOException- if an IO error occurs- See Also:
-
requestCredDeleg
public void requestCredDeleg(boolean requestDelegation) Request that this GSSCredential be allowed for delegation.- Parameters:
requestDelegation- true to allow/request delegation
-
setRequestMethod
May override the default GET method.- Parameters:
method- the HTTP method to use- See Also:
-