JBoss EAP从Legacy Security迁移至Elytron:默认安全域问询
JBoss Legacy默认安全域用途及Elytron迁移指南
一、三个默认安全域的用途
- other安全域:这是JBoss的默认认证域,所有未指定自定义安全域的部署应用都会自动使用它。配置里的
Remoting登录模块负责处理远程连接认证(比如CLI、EJB远程调用),RealmDirect模块直接调用JBoss内置Realm(比如PropertiesRealm)校验密码,password-stacking参数让两个模块共享认证凭证,避免重复验证。 - jboss-web-policy安全域:专门为Web应用提供授权策略的域,
Delegating策略模块将授权决策委托给底层安全Realm,确保Web应用的角色权限检查正常执行。 - jboss-ejb-policy安全域:为EJB组件提供授权策略的域,同样使用
Delegating模块,把EJB的权限验证委托给Realm,控制哪些用户能访问特定EJB方法。
二、迁移到Elytron Security的步骤
Elytron采用全新的组件模型,需要将Legacy安全域对应转换为Elytron组件,可通过JBoss CLI执行以下命令完成迁移:
- 创建Elytron安全域
对应Legacy的other安全域,创建关联默认Realm的Elytron安全域:
/subsystem=elytron/security-domain=other:add(realms=[{realm-name=ApplicationRealm, role-mapper=default-role-mapper}], default-realm=ApplicationRealm, permission-mapper=default-permission-mapper)
- 配置认证相关组件
替代Legacy的登录模块,创建认证配置和认证工厂:
/subsystem=elytron/authentication-configuration=other-auth-configuration:add(security-domain=other) /subsystem=elytron/authentication-factory=other-auth-factory:add(authentication-configuration=other-auth-configuration, security-domain=other)
- 配置授权策略并绑定到Web/EJB子系统
对应jboss-web-policy和jboss-ejb-policy,先创建授权配置,再绑定到对应子系统:
# 创建授权配置 /subsystem=elytron/authorization-configuration=web-authorization:add(security-domain=other) /subsystem=elytron/authorization-configuration=ejb-authorization:add(security-domain=other) # 绑定到Undertow(Web)子系统 /subsystem=undertow/application-security-domain=other:add(security-domain=other, http-authentication-factory=other-auth-factory) # 绑定到EJB3子系统 /subsystem=ejb3/application-security-domain=other:add(security-domain=other)
- 清理Legacy安全子系统(可选)
确认所有应用适配Elytron后,可删除Legacy安全子系统避免冲突:
/subsystem=security:remove()
三、迁移后原安全域被移除的说明
使用Elytron CLI迁移工具时,工具会自动将Legacy安全域配置转换为Elytron对应组件,同时删除原Legacy安全子系统的配置——这是正常行为。因为Elytron和Legacy安全子系统无法同时生效(除非配置兼容),迁移工具默认清理旧配置,确保Elytron成为唯一安全提供者。
若有旧应用依赖Legacy安全域名称,无需修改代码的话,可添加兼容映射:
/subsystem=elytron/legacy-security-domain=other:add(mapped-to=other) /subsystem=elytron/legacy-security-domain=jboss-web-policy:add(mapped-to=web-authorization) /subsystem=elytron/legacy-security-domain=jboss-ejb-policy:add(mapped-to=ejb-authorization)
这样旧应用调用Legacy安全域时,会自动映射到对应的Elytron组件。
内容的提问来源于stack exchange,提问作者Nega
相关产品推荐
相关产品推荐

