Spring-security、Tomcat 和 SPNEGO - 最佳方法
我正在寻找在 Tomcat 和 Windows 上为 spring-security 应用程序实现 SPNEGO/Kerberos 登录的最佳方法。我看过的候选人:
- Spring Security Kerberos Extension
- Waffle
- Apache httpd fronting with mod_auth_kerb 模块
- Apache httpd 与 mod_auth_sspi 模块
我对 Waffle 并没有留下深刻的印象mod_auth_sspi 似乎只支持 NTLMv1,所以这是不可行的。我确实看到了 Apache httpd 的价值,所以这似乎是一个很好的方法。我想知道这与 spring-security 的配合效果如何。谁做到了这一点?哪种方法是最好/最稳定的?
I'm looking for the best approach to achieve SPNEGO/Kerberos login for a spring-security application on Tomcat and Windows. Candidates i've looked at:
- Spring Security Kerberos Extension
- Waffle
- Apache httpd fronting with mod_auth_kerb module
- Apache httpd with mod_auth_sspi module
I wasn't super-impressed by Waffle and mod_auth_sspi only seems to support NTLMv1 so that is out. I do see a value in fronting with an Apache httpd so that seems like a good approach. How well does that play with spring-security though, I wonder. Who has done this? Which is the best/most stable approach?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
不要做任何开销。使用 Spring SEC 扩展。该产品在我们的环境中运行了一年多,运行良好。尽管它有一些改进的潜力。
Don't do any overhead. Use the Spring SEC Extension. That one works quite well on our environment for more than a year. Though it has the potention for some improvement.