Book Image

Mastering JBoss Enterprise Application Platform 7

By : Francesco Marchioni, Luigi Fugaro
Book Image

Mastering JBoss Enterprise Application Platform 7

By: Francesco Marchioni, Luigi Fugaro

Overview of this book

The JBoss Enterprise Application Platform (EAP) has been one of the most popular tools for Java developers to create modular, cloud-ready, and modern applications. It has achieved a reputation for architectural excellence and technical savvy, making it a solid and efficient environment for delivering your applications. The book will first introduce application server configuration and the management instruments that can be used to control the application server. Next, the focus will shift to enterprise solutions such as clustering, load balancing, and data caching; this will be the core of the book. We will also discuss services provided by the application server, such as database connectivity and logging. We focus on real-world example configurations and how to avoid common mistakes. Finally, we will implement the knowledge gained so far in terms of Docker containers and cloud availability using RedHat's OpenShift.
Table of Contents (20 chapters)
Mastering JBoss Enterprise Application Platform 7
Credits
About the Authors
About the Reviewer
www.PacktPub.com
Preface

Securing the management interfaces with LDAP


In the Testing the Kerberos login against management interfaces section, we discussed how to secure the management interfaces using the Kerberos ticketing system.

If you don't need that level of complexity in your infrastructure, but you still want to provide an adequate level of security, the recommended approach is to use a directory service. The directory service can be used both for authenticating the user and for granting a role to the user. If your management users will be all SuperUsers then it's enough to configure just the authentication layer. On the other hand, if you want to apply Role-Based Access Control (RBAC) on your management users then you have to configure the authorization part.

To get you started quickly with this topic, we can continue using the ApacheDS server contained in the kerberos-using-apacheds project, which contains some LDAP users along with the Kerberos configuration. Otherwise, you can download the full ApacheDS...