JBoss Projects: Security

Security projects provide authentication and authorization capabilities to JBoss products, most notably JBoss Application Server. In addition to standard J2EE security they also provide identity management functionality and single sign-on behaviour across multiple applications.

JBoss Security and Identity Management provides J2EE and custom security to JBoss products in addition to identity management. Authentication of users can be achieved using pluggable JAAS login modules with the resulting JAAS Subjects used for authorization. Support for a wide range of datastores is provided out-of-the-box and can be easily extended to meet the most demanding requirements.

JBoss Federated SSO (a sub-project of JBoss Security) provides a collection of components that software developers can easily integrate within their existing web applications to create a federation of trusted websites. Support for the SAML standard is included, in the form of a token marshaller, to securely propagate Federation Tokens over the network. Based on a pluggable architecure this can easily be changed for a different type of marshaller if required. By default the product ships with a provider to connect to an LDAP based Identity Store, although this too is pluggable if your identities reside elsewhere.

 

Security

JBoss Security and Identity Management
JBoss Federated SSO
Found a Security Vulnerability in a JBoss Product?

Please email either (security AT jboss DOT com) or (security AT jboss DOT org). We will treat your report with the utmost confidentiality and respect. We will not disclose your private information.
You can also visit the Red Hat Security Report PageRed Hat Security Team Page to report the vulnerability.

Latest Blogs

JBoss Tools on Twitter
Posted on Dec 2, 2008 4:57:04 PM by Max Andersen.

Structure prevents chaos
Posted on Dec 2, 2008 12:05:16 PM by Bob McWhirter.

How to write a plugin for JBossON, Jopr and RHQ available
Posted on Dec 2, 2008 11:07:00 AM by Heiko W. Rupp.

Latest Podcast

RichFaces/Ajax4jsf project discussion with Alexander Smirnov, JBoss Booth, JavaOne 2008 (ogg format)

Ajax4jsf project lead Alexander Smirnov spends a few minutes with JBoss.org/Dev Fu to discuss the history and future of Ajax4jsf. MP3 format is also available.


All Podcasts   ATOM

Developer Spotlight

Alex Loubyansky

Country: Ukraine
Title: CMP,JDO/JBoss Lead, Consultant
Status: Active

Bio: I was born in 1980 in Kiev by great woman Irene. She taught me Russian. When I grew up I met another Irene and she taught me English. Then I met JBoss and it taught me J2EE. Since that I mostly thin ... More Information