Jetty中ConfigurableSpnegoLoginService的工作原理及使用方法是什么?
Jetty ConfigurableSpnegoLoginService 仅认证模式使用示例
- 前置准备:
- 提前准备好服务端Kerberos配置文件
krb5.conf、服务主体对应的keytab文件 - 确保服务主体格式为
HTTP/你的服务域名@Realm名称 - 项目已引入jetty-security对应版本的依赖
- 提前准备好服务端Kerberos配置文件
import org.eclipse.jetty.security.Constraint; import org.eclipse.jetty.security.ConstraintMapping; import org.eclipse.jetty.security.ConstraintSecurityHandler; import org.eclipse.jetty.security.ConfigurableSpnegoLoginService; import org.eclipse.jetty.security.SpnegoAuthenticator; // 1. 初始化ConfigurableSpnegoLoginService ConfigurableSpnegoLoginService spnegoLoginService = new ConfigurableSpnegoLoginService(); // 配置Kerberos Realm名称 spnegoLoginService.setRealmName("你的Kerberos Realm名"); // 配置keytab文件本地路径 spnegoLoginService.setKeytabPath("/path/to/your/service.keytab"); // 配置krb5.conf文件本地路径 spnegoLoginService.setKrb5ConfigPath("/path/to/krb5.conf"); // 配置服务主体 spnegoLoginService.setServicePrincipalName("HTTP/your.service.domain@YOUR_REALM.COM"); // 关闭角色校验,跳过授权逻辑 spnegoLoginService.setCheckRoles(false); spnegoLoginService.start(); // 2. 配置认证约束,仅要求认证不校验角色 Constraint authConstraint = new Constraint(); authConstraint.setName(Constraint.__SPNEGO_AUTH); authConstraint.setAuthenticate(true); // 不设置任何必填角色,跳过授权逻辑 authConstraint.setRoles(new String[0]); // 3. 绑定到安全处理器 ConstraintSecurityHandler securityHandler = new ConstraintSecurityHandler(); securityHandler.setLoginService(spnegoLoginService); securityHandler.setAuthenticator(new SpnegoAuthenticator()); // 配置约束生效的路径范围 ConstraintMapping mapping = new ConstraintMapping(); mapping.setConstraint(authConstraint); mapping.setPathSpec("/*"); // 对全路径生效,可按需修改 securityHandler.addConstraintMapping(mapping); // 4. 最后将securityHandler绑定到你的Jetty ContextHandler即可使用
注意事项:
- 服务运行进程需要拥有keytab、krb5.conf文件的读取权限
- 客户端需要提前配置好Kerberos环境,请求时会自动携带SPNEGO票据完成认证
- 无需额外自定义IdentityService,默认实现即可满足仅认证的需求
内容的提问来源于stack exchange,提问作者texmelex
相关产品推荐
相关产品推荐

