You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Wildfly 20+配置双SSO提供商(MS AD与Azure SAML)可行性咨询

Wildfly 20+ 配置双SSO提供商(主AD+备用Azure SAML)方案

可行性结论

完全可行,但Wildfly原生SSO子系统不支持直接配置多提供商自动 fallback,需要基于Elytron认证链(authentication chain)扩展实现,或者结合自定义登录逻辑完成主备切换。

核心实现思路

Wildfly的Elytron子系统支持按优先级组合多个认证机制,通过设置认证模块的控制标志(control flag),可以实现"主认证失败则触发备用认证"的流程:

  • 优先配置MS AD的LDAP认证作为主提供商,使用ldap-realm对接AD服务器
  • 再配置Azure SAML的SAML2认证作为备用提供商,通过Elytron的SAML扩展或Keycloak适配器完成对接
  • 在认证链中给主认证模块设置sufficient标志(认证成功则跳过后续模块,失败则继续),备用模块设置required标志(必须成功)

关键配置片段

1. 配置MS AD的LDAP Realm

<security-realms>
  <ldap-realm name="ADRealm">
    <directory>
      <ldap-url>ldap://your-ad-domain-controller:389</ldap-url>
      <authentication>
        <simple-dn>CN=BindUser,OU=ServiceAccounts,DC=your-domain,DC=com</simple-dn>
        <credential-reference clear-text="BindPassword123"/>
      </authentication>
      <identity-mapping>
        <attribute-mapping>
          <attribute from="sAMAccountName" to="username"/>
          <attribute from="mail" to="email"/>
        </attribute-mapping>
      </identity-mapping>
    </directory>
  </ldap-realm>
</security-realms>

2. 配置Azure SAML的SAML Realm

<security-realms>
  <saml-realm name="AzureSAMLRealm">
    <saml-server>
      <entity-id>https://your-wildfly-app.com/saml/sp</entity-id>
      <keystore path="saml-keystore.jks" relative-to="jboss.server.config.dir" credential-reference clear-text="KeystorePass456"/>
      <identity-provider entity-id="https://login.microsoftonline.com/your-tenant-id/federationmetadata/2007-06/federationmetadata.xml" 
                         single-sign-on-url="https://login.microsoftonline.com/your-tenant-id/saml2"/>
    </saml-server>
  </saml-realm>
</security-realms>

3. 构建主备认证链

<authentication-client>
  <authentication-chains>
    <authentication-chain name="MultiSSOChain" send-forward-auth="true">
      <!-- 主认证:MS AD,成功则跳过后续,失败则进入Azure SAML -->
      <authentication-mechanism realm="ADRealm">
        <mechanism-name>LDAP</mechanism-name>
        <mechanism-configuration>
          <sufficient/>
        </mechanism-configuration>
      </authentication-mechanism>
      <!-- 备用认证:Azure SAML,必须成功 -->
      <authentication-mechanism realm="AzureSAMLRealm">
        <mechanism-name>SAML2</mechanism-name>
        <mechanism-configuration>
          <required/>
        </mechanism-configuration>
      </authentication-mechanism>
    </authentication-chain>
  </authentication-chains>
</authentication-client>

重要注意事项

  • 用户身份映射要统一:确保AD和Azure SAML返回的用户标识(如用户名)格式一致,避免权限验证时出现身份不匹配
  • Azure侧提前配置SP:在Azure AD中注册Wildfly作为服务提供商,配置ACS URL(一般为https://your-app-url/saml/acs)和断言属性映射
  • 测试fallback逻辑:模拟AD认证失败场景(比如输入错误密码、AD服务器不可用),验证是否自动跳转至Azure登录页
  • 复杂场景需自定义扩展:如果需要更灵活的切换规则(比如按用户组选择提供商),可以自定义AuthenticationMechanism实现类,注入到Elytron流程中

参考资源

  • Wildfly Elytron官方文档中「Authentication Chains」和「LDAP Realm Configuration」章节
  • Wildfly SAML2集成官方示例(重点关注SP侧的Realm配置步骤)
  • Wildfly社区论坛中关于多认证源组合的讨论案例

内容的提问来源于stack exchange,提问作者Siladam

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.14 18:35:30