You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

JBoss EAP从Legacy Security迁移至Elytron:默认安全域问询

JBoss Legacy默认安全域用途及Elytron迁移指南

一、三个默认安全域的用途

  • other安全域:这是JBoss的默认认证域,所有未指定自定义安全域的部署应用都会自动使用它。配置里的Remoting登录模块负责处理远程连接认证(比如CLI、EJB远程调用),RealmDirect模块直接调用JBoss内置Realm(比如PropertiesRealm)校验密码,password-stacking参数让两个模块共享认证凭证,避免重复验证。
  • jboss-web-policy安全域:专门为Web应用提供授权策略的域,Delegating策略模块将授权决策委托给底层安全Realm,确保Web应用的角色权限检查正常执行。
  • jboss-ejb-policy安全域:为EJB组件提供授权策略的域,同样使用Delegating模块,把EJB的权限验证委托给Realm,控制哪些用户能访问特定EJB方法。

二、迁移到Elytron Security的步骤

Elytron采用全新的组件模型,需要将Legacy安全域对应转换为Elytron组件,可通过JBoss CLI执行以下命令完成迁移:

  1. 创建Elytron安全域
    对应Legacy的other安全域,创建关联默认Realm的Elytron安全域:
/subsystem=elytron/security-domain=other:add(realms=[{realm-name=ApplicationRealm, role-mapper=default-role-mapper}], default-realm=ApplicationRealm, permission-mapper=default-permission-mapper)
  1. 配置认证相关组件
    替代Legacy的登录模块,创建认证配置和认证工厂:
/subsystem=elytron/authentication-configuration=other-auth-configuration:add(security-domain=other)
/subsystem=elytron/authentication-factory=other-auth-factory:add(authentication-configuration=other-auth-configuration, security-domain=other)
  1. 配置授权策略并绑定到Web/EJB子系统
    对应jboss-web-policy和jboss-ejb-policy,先创建授权配置,再绑定到对应子系统:
# 创建授权配置
/subsystem=elytron/authorization-configuration=web-authorization:add(security-domain=other)
/subsystem=elytron/authorization-configuration=ejb-authorization:add(security-domain=other)

# 绑定到Undertow(Web)子系统
/subsystem=undertow/application-security-domain=other:add(security-domain=other, http-authentication-factory=other-auth-factory)

# 绑定到EJB3子系统
/subsystem=ejb3/application-security-domain=other:add(security-domain=other)
  1. 清理Legacy安全子系统(可选)
    确认所有应用适配Elytron后,可删除Legacy安全子系统避免冲突:
/subsystem=security:remove()

三、迁移后原安全域被移除的说明

使用Elytron CLI迁移工具时,工具会自动将Legacy安全域配置转换为Elytron对应组件,同时删除原Legacy安全子系统的配置——这是正常行为。因为Elytron和Legacy安全子系统无法同时生效(除非配置兼容),迁移工具默认清理旧配置,确保Elytron成为唯一安全提供者。

若有旧应用依赖Legacy安全域名称,无需修改代码的话,可添加兼容映射:

/subsystem=elytron/legacy-security-domain=other:add(mapped-to=other)
/subsystem=elytron/legacy-security-domain=jboss-web-policy:add(mapped-to=web-authorization)
/subsystem=elytron/legacy-security-domain=jboss-ejb-policy:add(mapped-to=ejb-authorization)

这样旧应用调用Legacy安全域时,会自动映射到对应的Elytron组件。

内容的提问来源于stack exchange,提问作者Nega

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 02:16:10