Search in sources :

Example 1 with KerberosConfig

use of org.apache.directory.server.kerberos.KerberosConfig in project undertow by undertow-io.

the class KerberosKDCUtil method startKDC.

private static void startKDC() throws Exception {
    kdcServer = new KdcServer();
    kdcServer.setServiceName("Test KDC");
    kdcServer.setSearchBaseDn("ou=users,dc=undertow,dc=io");
    KerberosConfig config = kdcServer.getConfig();
    config.setServicePrincipal("krbtgt/UNDERTOW.IO@UNDERTOW.IO");
    config.setPrimaryRealm("UNDERTOW.IO");
    config.setPaEncTimestampRequired(false);
    UdpTransport udp = new UdpTransport("0.0.0.0", KDC_PORT);
    kdcServer.addTransports(udp);
    kdcServer.setDirectoryService(directoryService);
    kdcServer.start();
}
Also used : UdpTransport(org.apache.directory.server.protocol.shared.transport.UdpTransport) KerberosConfig(org.apache.directory.server.kerberos.KerberosConfig) KdcServer(org.apache.directory.server.kerberos.kdc.KdcServer)

Example 2 with KerberosConfig

use of org.apache.directory.server.kerberos.KerberosConfig in project wildfly by wildfly.

the class NoReplayKdcServer method createKdcServer.

// Private methods -------------------------------------------------------
/**
 * Creates and starts {@link KdcServer} instance based on given configuration.
 *
 * @param createKdcServer
 * @param directoryService
 * @param startPort
 * @return
 */
private static KdcServer createKdcServer(CreateKdcServer createKdcServer, DirectoryService directoryService, int startPort, String bindAddress) {
    if (createKdcServer == null) {
        return null;
    }
    KerberosConfig kdcConfig = new KerberosConfig();
    kdcConfig.setServicePrincipal(createKdcServer.kdcPrincipal());
    kdcConfig.setPrimaryRealm(createKdcServer.primaryRealm());
    kdcConfig.setMaximumTicketLifetime(createKdcServer.maxTicketLifetime());
    kdcConfig.setMaximumRenewableLifetime(createKdcServer.maxRenewableLifetime());
    kdcConfig.setPaEncTimestampRequired(false);
    KdcServer kdcServer = new NoReplayKdcServer(kdcConfig);
    kdcServer.setSearchBaseDn(createKdcServer.searchBaseDn());
    CreateTransport[] transportBuilders = createKdcServer.transports();
    if (transportBuilders == null) {
        // create only UDP transport if none specified
        UdpTransport defaultTransport = new UdpTransport(bindAddress, AvailablePortFinder.getNextAvailable(startPort));
        kdcServer.addTransports(defaultTransport);
    } else if (transportBuilders.length > 0) {
        for (CreateTransport transportBuilder : transportBuilders) {
            String protocol = transportBuilder.protocol();
            int port = transportBuilder.port();
            int nbThreads = transportBuilder.nbThreads();
            int backlog = transportBuilder.backlog();
            final String address = bindAddress != null ? bindAddress : transportBuilder.address();
            if (port == -1) {
                port = AvailablePortFinder.getNextAvailable(startPort);
                startPort = port + 1;
            }
            if (protocol.equalsIgnoreCase("TCP")) {
                Transport tcp = new TcpTransport(address, port, nbThreads, backlog);
                kdcServer.addTransports(tcp);
            } else if (protocol.equalsIgnoreCase("UDP")) {
                UdpTransport udp = new UdpTransport(address, port);
                kdcServer.addTransports(udp);
            } else {
                throw new IllegalArgumentException(I18n.err(I18n.ERR_689, protocol));
            }
        }
    }
    CreateChngPwdServer[] createChngPwdServers = createKdcServer.chngPwdServer();
    if (createChngPwdServers.length > 0) {
        CreateChngPwdServer createChngPwdServer = createChngPwdServers[0];
        ChangePasswordConfig config = new ChangePasswordConfig(kdcConfig);
        config.setServicePrincipal(createChngPwdServer.srvPrincipal());
        ChangePasswordServer chngPwdServer = new ChangePasswordServer(config);
        for (CreateTransport transportBuilder : createChngPwdServer.transports()) {
            Transport t = createTransport(transportBuilder, startPort);
            startPort = t.getPort() + 1;
            chngPwdServer.addTransports(t);
        }
        chngPwdServer.setDirectoryService(directoryService);
        kdcServer.setChangePwdServer(chngPwdServer);
    }
    kdcServer.setDirectoryService(directoryService);
    // Launch the server
    try {
        kdcServer.start();
    } catch (Exception e) {
        e.printStackTrace();
    }
    return kdcServer;
}
Also used : UdpTransport(org.apache.directory.server.protocol.shared.transport.UdpTransport) KerberosConfig(org.apache.directory.server.kerberos.KerberosConfig) CreateTransport(org.apache.directory.server.annotations.CreateTransport) ChangePasswordServer(org.apache.directory.server.kerberos.changepwd.ChangePasswordServer) IOException(java.io.IOException) LdapInvalidDnException(org.apache.directory.api.ldap.model.exception.LdapInvalidDnException) ChangePasswordConfig(org.apache.directory.server.kerberos.ChangePasswordConfig) CreateChngPwdServer(org.apache.directory.server.annotations.CreateChngPwdServer) TcpTransport(org.apache.directory.server.protocol.shared.transport.TcpTransport) CreateTransport(org.apache.directory.server.annotations.CreateTransport) UdpTransport(org.apache.directory.server.protocol.shared.transport.UdpTransport) TcpTransport(org.apache.directory.server.protocol.shared.transport.TcpTransport) Transport(org.apache.directory.server.protocol.shared.transport.Transport) KdcServer(org.apache.directory.server.kerberos.kdc.KdcServer) CreateKdcServer(org.apache.directory.server.annotations.CreateKdcServer)

Example 3 with KerberosConfig

use of org.apache.directory.server.kerberos.KerberosConfig in project sonarqube by SonarSource.

the class ApacheDS method startKdcServer.

private ApacheDS startKdcServer() throws IOException, LdapOperationException {
    int port = AvailablePortFinder.getNextAvailable(6088);
    KerberosConfig kdcConfig = new KerberosConfig();
    kdcConfig.setServicePrincipal("krbtgt/EXAMPLE.ORG@EXAMPLE.ORG");
    kdcConfig.setPrimaryRealm("EXAMPLE.ORG");
    kdcConfig.setPaEncTimestampRequired(false);
    kdcServer = new KdcServer(kdcConfig);
    kdcServer.setSearchBaseDn("dc=example,dc=org");
    kdcServer.addTransports(new UdpTransport("localhost", port));
    kdcServer.setDirectoryService(directoryService);
    kdcServer.start();
    FileUtils.writeStringToFile(new File("target/krb5.conf"), "" + "[libdefaults]\n" + "    default_realm = EXAMPLE.ORG\n" + "\n" + "[realms]\n" + "    EXAMPLE.ORG = {\n" + "        kdc = localhost:" + port + "\n" + "    }\n" + "\n" + "[domain_realm]\n" + "    .example.org = EXAMPLE.ORG\n" + "    example.org = EXAMPLE.ORG\n", StandardCharsets.UTF_8.name());
    return this;
}
Also used : UdpTransport(org.apache.directory.server.protocol.shared.transport.UdpTransport) KerberosConfig(org.apache.directory.server.kerberos.KerberosConfig) File(java.io.File) KdcServer(org.apache.directory.server.kerberos.kdc.KdcServer)

Example 4 with KerberosConfig

use of org.apache.directory.server.kerberos.KerberosConfig in project sonarqube by SonarSource.

the class ApacheDS method startKdcServer.

private ApacheDS startKdcServer() throws IOException, LdapOperationException {
    int port = AvailablePortFinder.getNextAvailable(6088);
    KerberosConfig kdcConfig = new KerberosConfig();
    kdcConfig.setServicePrincipal("krbtgt/EXAMPLE.ORG@EXAMPLE.ORG");
    kdcConfig.setPrimaryRealm("EXAMPLE.ORG");
    kdcConfig.setPaEncTimestampRequired(false);
    kdcServer = new KdcServer(kdcConfig);
    kdcServer.setSearchBaseDn("dc=example,dc=org");
    kdcServer.addTransports(new UdpTransport("localhost", port));
    kdcServer.setDirectoryService(directoryService);
    kdcServer.start();
    FileUtils.writeStringToFile(new File("target/krb5.conf"), "" + "[libdefaults]\n" + "    default_realm = EXAMPLE.ORG\n" + "\n" + "[realms]\n" + "    EXAMPLE.ORG = {\n" + "        kdc = localhost:" + port + "\n" + "    }\n" + "\n" + "[domain_realm]\n" + "    .example.org = EXAMPLE.ORG\n" + "    example.org = EXAMPLE.ORG\n", StandardCharsets.UTF_8.name());
    return this;
}
Also used : UdpTransport(org.apache.directory.server.protocol.shared.transport.UdpTransport) KerberosConfig(org.apache.directory.server.kerberos.KerberosConfig) File(java.io.File) KdcServer(org.apache.directory.server.kerberos.kdc.KdcServer)

Example 5 with KerberosConfig

use of org.apache.directory.server.kerberos.KerberosConfig in project keycloak by keycloak.

the class KerberosEmbeddedServer method createAndStartKdcServer.

protected KdcServer createAndStartKdcServer() throws Exception {
    KerberosConfig kdcConfig = new KerberosConfig();
    kdcConfig.setServicePrincipal("krbtgt/" + this.kerberosRealm + "@" + this.kerberosRealm);
    kdcConfig.setPrimaryRealm(this.kerberosRealm);
    kdcConfig.setMaximumTicketLifetime(60000 * 1440);
    kdcConfig.setMaximumRenewableLifetime(60000 * 10080);
    kdcConfig.setPaEncTimestampRequired(false);
    Set<EncryptionType> encryptionTypes = convertEncryptionTypes();
    kdcConfig.setEncryptionTypes(encryptionTypes);
    kdcServer = new NoReplayKdcServer(kdcConfig);
    kdcServer.setSearchBaseDn(this.baseDN);
    UdpTransport udp = new UdpTransport(this.bindHost, this.kdcPort);
    kdcServer.addTransports(udp);
    kdcServer.setDirectoryService(directoryService);
    // Launch the server
    kdcServer.start();
    return kdcServer;
}
Also used : UdpTransport(org.apache.directory.server.protocol.shared.transport.UdpTransport) EncryptionType(org.apache.directory.shared.kerberos.codec.types.EncryptionType) KerberosConfig(org.apache.directory.server.kerberos.KerberosConfig)

Aggregations

KerberosConfig (org.apache.directory.server.kerberos.KerberosConfig)5 UdpTransport (org.apache.directory.server.protocol.shared.transport.UdpTransport)5 KdcServer (org.apache.directory.server.kerberos.kdc.KdcServer)4 File (java.io.File)2 IOException (java.io.IOException)1 LdapInvalidDnException (org.apache.directory.api.ldap.model.exception.LdapInvalidDnException)1 CreateChngPwdServer (org.apache.directory.server.annotations.CreateChngPwdServer)1 CreateKdcServer (org.apache.directory.server.annotations.CreateKdcServer)1 CreateTransport (org.apache.directory.server.annotations.CreateTransport)1 ChangePasswordConfig (org.apache.directory.server.kerberos.ChangePasswordConfig)1 ChangePasswordServer (org.apache.directory.server.kerberos.changepwd.ChangePasswordServer)1 TcpTransport (org.apache.directory.server.protocol.shared.transport.TcpTransport)1 Transport (org.apache.directory.server.protocol.shared.transport.Transport)1 EncryptionType (org.apache.directory.shared.kerberos.codec.types.EncryptionType)1