Natively, Shibboleth supports a variety of authentication methods, among those the most general (and default) is Password-based authentication. It performs a username-password pair check against a user backend. The backend could be provided in many ways. Off the shelves Shibboleth provides following:
- LDAP-based, uses an LDAP source;
- JAAS-based, uses a JAAS authentication scheme;
- Kerberos, uses a Kerberos authentication system.
JAAS is the most flexible, because allows to use any backend, provided that it is interfaced through the JAAS (Java Autentication and Authorization Service) scheme. The drawback is that you need to write the JAAS Class to interface your backend.
This guide shows you how to implement JAAS authetication for Shibboleth using a relational DBMS such as MySQL, Oracle or MSSQL. Note that this describes how to autheticate against a relational DBMS, not how to acquire attributes from it, which is possible out of the box.
- Prerequisites
- JAAS custom classes creation
- JAAS custom classes deployment
- Shibboleth configuration
Prerequisites
This guide assumes the following:
- Familiarity with Shibboleth IDP.
- You have a Shibboleth IDP installation already running on your system. If not, refer to official installation instructions at https://wiki.shibboleth.net/confluence/display/IDP30/Installation.
- You have a relational database of your choice containing a user table with username and (hashed) password columns, as follows (column names maybe different)
| username | password | salt_column (optional) | other_data |
|---|---|---|---|
| - | - | - | - |
JAAS CUSTOM CLASSES CREATION
For authentican purposes, a Java class must inherit from the LoginModule abstract class, and must implement five methods:
- initialize
- login
- commit
- abort
- logout
The complete code repository implementing JAAS LoginModule for Relational DBMS Authentication is available at: https://github.com/robertogallea/jaas_relational_login or you could download the compiled JAR from this page.
Build it to obtain a jar archive, that has to be deployed to your shibboleth IDP instance.
JAAS Custom Class deployment
After building the JAAS module, you are required to deploy to the IDP application, in order to make it available for use. This is accomplished following some steps:
- Copy the archive JAAS_relational_login.jar under /edit-webapp/WEB-INF/lib
- Download the JDBC driver for your DBMS, for example, for Oracle is ojdbc7.jar and copy it under /edit-webapp/WEB-INF/lib
- Run
/bin/build.shscript to rebuild the IDP web application - If required, deploy the newly built application into your container (tomcat, jetty, IIs, etc.)
Shibboleth Configuration
This is the most important part, some configurations are required:
- Creation of jaas.config
- Setting JAAS as authenticator for Shibboleth IDP
Creation of jaas.config
Create or replace the file jaas.config under /conf/authn using the following content:
1/** Login Configuration for the JAAS Sample Application **/
2
3ShibUserPassAuth {
4 relationalLogin.DBLogin required debug=true
5 dbDriver="oracle.jdbc.driver.OracleDriver"
6 userTable="userTableName"
7 userColumn="username"
8 passColumn="password_sha"
9 dbURL="your_db_url"
10 dbUser="dbUserName"
11 dbPassword="dbPassword"
12 hashAlgorithm="SHA-512"
13 saltColumn=""
14 errorMessage="Invalid password";
15};
edit it as required including the relevant data according to your DBMS configuration.
Note: if in your table you have a salt stored in a column, set it in saltColumn, parameter, otherwise leave it blank, or omit it. The salted hash will be calculated as hash(password + salt)
Note2: in the case you wish to use cleartext password, leave hashAlgorithm blank or omit it.
Note3: Available hashing algorithms are DBMS native hashing functions (e.g. SHA-1, SHA-256) and bcrypt.
Setting JAAS as authenticator for Shibboleth IDP
Open the file /conf/authn/password_authn_config.xml, and modify it from:
1 <!-- <import resource="jaas-authn-config.xml" /> -->
2 <!-- <import resource="krb5-authn-config.xml" /> -->
3 <import resource="ldap-authn-config.xml">
to
1 <import resource="jaas-authn-config.xml">
2 <!-- <import resource="krb5-authn-config.xml" /> -->
3 <!-- <import resource="ldap-authn-config.xml" /> -->
to disable ldap authenticator and enable jaas authenticator.
Note: Do not change jaas.config filename or the login context name inside it (ShibUserPassAuth) to something else, otherwise you will need to change the content of the file /conf/authn/jaas_authn_config.xml accordingly.
You should be done, try to restart your container to check if everything is right and login works.