I'd like to have delegated credentials be available to tomcat servlets
and any processes executed in the tomcat environment. I am using
tomcat behind apache with the AJP connector (with the mod_proxy_ajp
apache module providing the connection to apache).
One of the problems is that (depending on the apache connector--
I believe) no information regarding the apache environment is transferred
over to the tomcat service. Therefore, even though mod_auth_kerb can
be configured to save credentials, the file cache name does not get
transferred to tomcat. Furthermore, if you have tomcat running with
a separate user's privileges, the file cache saved by mod_auth_kerb
is not readable by the tomcat process.
I've come up with two possible solutions:
1. Send tomcat the location of the file cache: (I'm using this solution right now)
a. Tomcat must run as the same user as does apache
b. The location of the cache must be added to the in-bound HTTP headers:
In version 5.4, this involves a one-line addition at
src/mod_auth_kerb.c:871
apr_table_setn(r->subprocess_env, "KRB5CCNAME", ccname);
+ apr_table_setn(r->headers_in, "KRB5CCNAME", ccname);
This way, the location of the file cache is stored in the headers for tomcat to examine.
Because tomcat runs as the apache user, there are no file permission problems.
I imagine that if this is the best solution, there ought to be a configuration option
to select whether you want to store the location of the file cache in the in-
bound headers.
2. Encode the actual cache using base64 encoding and save the result to the in-bound headers.
Using this solution, apache and tomcat can remain as processes of separate users,
thereby allowing apache to run under SELinux or similar restricted mode without effecting
the backend tomcat processes.
If this were the best option, I think it would be necessary to have a configuration option
that requests this functionality explicitly.
Is there already a better solution out there? If not, which of these two possible
solutions would be deemed best?
solution #1 is very easy to implement as it only involves adding one line to mod_auth_kerb.c.
Can we get this functionality in mod_auth_kerb?
Thanks