Wildfly 20+配置双SSO提供商(MS AD与Azure SAML)可行性咨询
Wildfly 20+ 配置双SSO提供商(主AD+备用Azure SAML)方案
可行性结论
完全可行,但Wildfly原生SSO子系统不支持直接配置多提供商自动 fallback,需要基于Elytron认证链(authentication chain)扩展实现,或者结合自定义登录逻辑完成主备切换。
核心实现思路
Wildfly的Elytron子系统支持按优先级组合多个认证机制,通过设置认证模块的控制标志(control flag),可以实现"主认证失败则触发备用认证"的流程:
- 优先配置MS AD的LDAP认证作为主提供商,使用
ldap-realm对接AD服务器 - 再配置Azure SAML的SAML2认证作为备用提供商,通过Elytron的SAML扩展或Keycloak适配器完成对接
- 在认证链中给主认证模块设置
sufficient标志(认证成功则跳过后续模块,失败则继续),备用模块设置required标志(必须成功)
关键配置片段
1. 配置MS AD的LDAP Realm
<security-realms> <ldap-realm name="ADRealm"> <directory> <ldap-url>ldap://your-ad-domain-controller:389</ldap-url> <authentication> <simple-dn>CN=BindUser,OU=ServiceAccounts,DC=your-domain,DC=com</simple-dn> <credential-reference clear-text="BindPassword123"/> </authentication> <identity-mapping> <attribute-mapping> <attribute from="sAMAccountName" to="username"/> <attribute from="mail" to="email"/> </attribute-mapping> </identity-mapping> </directory> </ldap-realm> </security-realms>
2. 配置Azure SAML的SAML Realm
<security-realms> <saml-realm name="AzureSAMLRealm"> <saml-server> <entity-id>https://your-wildfly-app.com/saml/sp</entity-id> <keystore path="saml-keystore.jks" relative-to="jboss.server.config.dir" credential-reference clear-text="KeystorePass456"/> <identity-provider entity-id="https://login.microsoftonline.com/your-tenant-id/federationmetadata/2007-06/federationmetadata.xml" single-sign-on-url="https://login.microsoftonline.com/your-tenant-id/saml2"/> </saml-server> </saml-realm> </security-realms>
3. 构建主备认证链
<authentication-client> <authentication-chains> <authentication-chain name="MultiSSOChain" send-forward-auth="true"> <!-- 主认证:MS AD,成功则跳过后续,失败则进入Azure SAML --> <authentication-mechanism realm="ADRealm"> <mechanism-name>LDAP</mechanism-name> <mechanism-configuration> <sufficient/> </mechanism-configuration> </authentication-mechanism> <!-- 备用认证:Azure SAML,必须成功 --> <authentication-mechanism realm="AzureSAMLRealm"> <mechanism-name>SAML2</mechanism-name> <mechanism-configuration> <required/> </mechanism-configuration> </authentication-mechanism> </authentication-chain> </authentication-chains> </authentication-client>
重要注意事项
- 用户身份映射要统一:确保AD和Azure SAML返回的用户标识(如用户名)格式一致,避免权限验证时出现身份不匹配
- Azure侧提前配置SP:在Azure AD中注册Wildfly作为服务提供商,配置ACS URL(一般为
https://your-app-url/saml/acs)和断言属性映射 - 测试fallback逻辑:模拟AD认证失败场景(比如输入错误密码、AD服务器不可用),验证是否自动跳转至Azure登录页
- 复杂场景需自定义扩展:如果需要更灵活的切换规则(比如按用户组选择提供商),可以自定义
AuthenticationMechanism实现类,注入到Elytron流程中
参考资源
- Wildfly Elytron官方文档中「Authentication Chains」和「LDAP Realm Configuration」章节
- Wildfly SAML2集成官方示例(重点关注SP侧的Realm配置步骤)
- Wildfly社区论坛中关于多认证源组合的讨论案例
内容的提问来源于stack exchange,提问作者Siladam
相关产品推荐
相关产品推荐

