Example 1 with SecurityCredentials

use of in project ignite by apache.

the class GridClientConnectionManagerAdapter method connect.

 * Create new connection to specified server.
 * @param nodeId {@code UUID} of node for mapping with connection.
 *      {@code null} if no need of mapping.
 * @param addr Remote socket to connect.
 * @return Established connection.
 * @throws IOException If connection failed.
 * @throws GridClientException If protocol error happened.
 * @throws InterruptedException If thread was interrupted before connection was established.
protected GridClientConnection connect(@Nullable UUID nodeId, InetSocketAddress addr) throws IOException, GridClientException, InterruptedException {
    try {
        GridClientConnection old = conns.get(addr);
        if (old != null) {
            if (old.isClosed()) {
                conns.remove(addr, old);
                if (nodeId != null)
                    nodeConns.remove(nodeId, old);
            } else {
                if (nodeId != null)
                    nodeConns.put(nodeId, old);
                return old;
        SecurityCredentials cred = null;
        try {
            if (cfg.getSecurityCredentialsProvider() != null)
                cred = cfg.getSecurityCredentialsProvider().credentials();
        } catch (IgniteCheckedException e) {
            throw new GridClientException("Failed to obtain client credentials.", e);
        GridClientConnection conn;
        if (cfg.getProtocol() == GridClientProtocol.TCP) {
            GridClientMarshaller marsh = cfg.getMarshaller();
            try {
                conn = new GridClientNioTcpConnection(srv, clientId, addr, sslCtx, pingExecutor, cfg.getConnectTimeout(), cfg.getPingInterval(), cfg.getPingTimeout(), cfg.isTcpNoDelay(), marsh, marshId, top, cred, cfg.getUserAttributes());
            } catch (GridClientException e) {
                if (marsh instanceof GridClientZipOptimizedMarshaller) {
                    log.warning("Failed to connect with GridClientZipOptimizedMarshaller," + " trying to fallback to default marshaller: " + e);
                    conn = new GridClientNioTcpConnection(srv, clientId, addr, sslCtx, pingExecutor, cfg.getConnectTimeout(), cfg.getPingInterval(), cfg.getPingTimeout(), cfg.isTcpNoDelay(), ((GridClientZipOptimizedMarshaller) marsh).defaultMarshaller(), marshId, top, cred, cfg.getUserAttributes());
                } else
                    throw e;
        } else
            throw new GridServerUnreachableException("Failed to create client (protocol is not supported): " + cfg.getProtocol());
        old = conns.putIfAbsent(addr, conn);
        assert old == null;
        if (nodeId != null)
            nodeConns.put(nodeId, conn);
        return conn;
    } finally {
Also used : GridClientException(org.apache.ignite.internal.client.GridClientException) GridServerUnreachableException(org.apache.ignite.internal.client.GridServerUnreachableException) SecurityCredentials( IgniteCheckedException(org.apache.ignite.IgniteCheckedException) GridClientMarshaller(org.apache.ignite.internal.client.marshaller.GridClientMarshaller) GridClientZipOptimizedMarshaller(org.apache.ignite.internal.client.marshaller.optimized.GridClientZipOptimizedMarshaller)

Example 2 with SecurityCredentials

use of in project ignite by apache.

the class GridClientConfiguration method load.

 * Load client configuration from the properties map.
 * @param prefix Prefix for the client properties.
 * @param in Properties map to load configuration from.
 * @throws GridClientException If parsing configuration failed.
public void load(String prefix, Properties in) throws GridClientException {
    while (prefix.endsWith(".")) prefix = prefix.substring(0, prefix.length() - 1);
    if (!prefix.isEmpty())
        prefix += ".";
    String balancer = in.getProperty(prefix + "balancer");
    String connectTimeout = in.getProperty(prefix + "connectTimeout");
    String cred = in.getProperty(prefix + "credentials");
    String autoFetchMetrics = in.getProperty(prefix + "autoFetchMetrics");
    String autoFetchAttrs = in.getProperty(prefix + "autoFetchAttributes");
    String maxConnIdleTime = in.getProperty(prefix + "idleTimeout");
    String proto = in.getProperty(prefix + "protocol");
    String srvrs = in.getProperty(prefix + "servers");
    String tcpNoDelay = in.getProperty(prefix + "tcp.noDelay");
    String topRefreshFreq = in.getProperty(prefix + "topology.refresh");
    String sslEnabled = in.getProperty(prefix + "ssl.enabled");
    String sslProto = in.getProperty(prefix + "ssl.protocol");
    String sslKeyAlg = in.getProperty(prefix + "ssl.key.algorithm");
    String keyStorePath = in.getProperty(prefix + "ssl.keystore.location");
    String keyStorePwd = in.getProperty(prefix + "ssl.keystore.password");
    String keyStoreType = in.getProperty(prefix + "ssl.keystore.type");
    String trustStorePath = in.getProperty(prefix + "ssl.truststore.location");
    String trustStorePwd = in.getProperty(prefix + "ssl.truststore.password");
    String trustStoreType = in.getProperty(prefix + "ssl.truststore.type");
    String dataCfgs = in.getProperty(prefix + "data.configurations");
    if (!F.isEmpty(connectTimeout))
    if (!F.isEmpty(cred)) {
        int idx = cred.indexOf(':');
        if (idx >= 0 && idx < cred.length() - 1) {
            setSecurityCredentialsProvider(new SecurityCredentialsBasicProvider(new SecurityCredentials(cred.substring(0, idx), cred.substring(idx + 1))));
        } else {
            setSecurityCredentialsProvider(new SecurityCredentialsBasicProvider(new SecurityCredentials(null, null, cred)));
    if (!F.isEmpty(autoFetchMetrics))
    if (!F.isEmpty(autoFetchAttrs))
    if (!F.isEmpty(maxConnIdleTime))
    if (!F.isEmpty(proto))
    if (!F.isEmpty(srvrs))
        setServers(Arrays.asList(srvrs.replaceAll("\\s+", "").split(",")));
    if (!F.isEmpty(tcpNoDelay))
    if (!F.isEmpty(topRefreshFreq))
    if (!F.isEmpty(sslEnabled) && Boolean.parseBoolean(sslEnabled)) {
        GridSslBasicContextFactory factory = new GridSslBasicContextFactory();
        factory.setProtocol(F.isEmpty(sslProto) ? DFLT_SSL_PROTOCOL : sslProto);
        factory.setKeyAlgorithm(F.isEmpty(sslKeyAlg) ? DFLT_KEY_ALGORITHM : sslKeyAlg);
        if (F.isEmpty(keyStorePath))
            throw new IllegalArgumentException("SSL key store location is not specified.");
        if (keyStorePwd != null)
        factory.setKeyStoreType(F.isEmpty(keyStoreType) ? DFLT_STORE_TYPE : keyStoreType);
        if (F.isEmpty(trustStorePath))
        else {
            if (trustStorePwd != null)
            factory.setTrustStoreType(F.isEmpty(trustStoreType) ? DFLT_STORE_TYPE : trustStoreType);
    if (!F.isEmpty(dataCfgs)) {
        String[] names = dataCfgs.replaceAll("\\s+", "").split(",");
        Collection<GridClientDataConfiguration> list = new ArrayList<>();
        for (String cfgName : names) {
            if (F.isEmpty(cfgName))
            String name = in.getProperty(prefix + "data." + cfgName + ".name");
            String bal = in.getProperty(prefix + "data." + cfgName + ".balancer");
            String aff = in.getProperty(prefix + "data." + cfgName + ".affinity");
            GridClientDataConfiguration dataCfg = new GridClientDataConfiguration();
            dataCfg.setName(F.isEmpty(name) ? null : name);
Also used : SecurityCredentials( GridSslBasicContextFactory(org.apache.ignite.internal.client.ssl.GridSslBasicContextFactory) ArrayList(java.util.ArrayList) SecurityCredentialsBasicProvider(

Example 3 with SecurityCredentials

use of in project ignite by apache.

the class IgniteAuthenticationProcessor method authenticate.

 * {@inheritDoc}
public SecurityContext authenticate(AuthenticationContext authCtx) throws IgniteCheckedException {
    SecurityCredentials creds = authCtx.credentials();
    String login = (String) creds.getLogin();
    if (F.isEmpty(login))
        throw new IgniteAccessControlException("The user name or password is incorrect [userName=" + login + ']');
    String passwd = (String) creds.getPassword();
    UUID subjId;
    if (ctx.clientNode()) {
        if (ctx.discovery().aliveServerNodes().isEmpty()) {
            throw new IgniteAccessControlException("No alive server node was found to which the authentication" + " operation could be delegated. It is possible that the client node has been started with the" + " \"forceServerMode\" flag enabled and no server node had been started yet.");
        AuthenticateFuture fut;
        do {
            synchronized (mux) {
                ClusterNode rndNode = U.randomServerNode(ctx);
                fut = new AuthenticateFuture(;
                UserAuthenticateRequestMessage msg = new UserAuthenticateRequestMessage(login, passwd);
                authFuts.put(, fut);
      , GridTopic.TOPIC_AUTH, msg, GridIoPolicy.SYSTEM_POOL);
        } while (fut.retry());
        subjId = toSubjectId(login);
    } else
        subjId = authenticateOnServer(login, passwd);
    return new SecurityContextImpl(subjId, login, authCtx.subjectType(), authCtx.address());
Also used : ClusterNode(org.apache.ignite.cluster.ClusterNode) SecurityCredentials( UUID(java.util.UUID)

Example 4 with SecurityCredentials

use of in project ignite by apache.

the class GridRestProcessor method authenticate.

 * Authenticates remote client.
 * @param req Request to authenticate.
 * @return Authentication subject context.
 * @throws IgniteCheckedException If authentication failed.
private SecurityContext authenticate(GridRestRequest req, Session ses) throws IgniteCheckedException {
    assert req.clientId() != null;
    AuthenticationContext authCtx = new AuthenticationContext();
    SecurityCredentials creds = credentials(req);
    if (creds.getLogin() == null) {
        SecurityCredentials sesCreds = ses.creds;
        if (sesCreds != null)
            creds = ses.creds;
    } else
        ses.creds = creds;
    SecurityContext subjCtx =;
    if (subjCtx == null) {
        if (req.credentials() == null)
            throw new IgniteCheckedException("Failed to authenticate remote client (secure session SPI not set?): " + req);
        throw new IgniteCheckedException("Failed to authenticate remote client (invalid credentials?): " + req);
    return subjCtx;
Also used : SecurityCredentials( AuthenticationContext( IgniteCheckedException(org.apache.ignite.IgniteCheckedException) OperationSecurityContext( SecurityContext(

Example 5 with SecurityCredentials

use of in project ignite by apache.

the class GridRestProcessor method credentials.

 * Extract credentials from request.
 * @param req Request.
 * @return Security credentials.
private SecurityCredentials credentials(GridRestRequest req) {
    Object creds = req.credentials();
    if (creds instanceof SecurityCredentials)
        return (SecurityCredentials) creds;
    if (creds instanceof String) {
        String credStr = (String) creds;
        int idx = credStr.indexOf(':');
        return idx >= 0 && idx < credStr.length() ? new SecurityCredentials(credStr.substring(0, idx), credStr.substring(idx + 1)) : new SecurityCredentials(credStr, null);
    SecurityCredentials cred = new SecurityCredentials();
    return cred;
Also used : SecurityCredentials(


