public class LockOutRealm extends CombinedRealm
| Modifier and Type | Class and Description |
|---|---|
protected static class |
LockOutRealm.LockRecord |
RealmBase.AllRolesModeLifecycle.SingleUse| Modifier and Type | Field and Description |
|---|---|
protected int |
cacheRemovalWarningTime
If a failed user is removed from the cache because the cache is too big before it has been in the cache for at
least this period of time (in seconds) a warning message will be logged.
|
protected int |
cacheSize
Number of users that have failed authentication to keep in cache.
|
protected java.util.Map<java.lang.String,LockOutRealm.LockRecord> |
failedUsers
Users whose last authentication attempt failed.
|
protected int |
failureCount
The number of times in a row a user has to fail authentication to be locked out.
|
protected int |
lockOutTime
The time (in seconds) a user is locked out for after too many authentication failures.
|
realmsallRolesMode, container, containerLog, realmPath, sm, stripRealmForGss, support, USER_ATTRIBUTES_DELIMITER, USER_ATTRIBUTES_WILDCARD, userAttributes, userAttributesList, validate, x509UsernameRetriever, x509UsernameRetrieverClassNamemserverAFTER_DESTROY_EVENT, AFTER_INIT_EVENT, AFTER_START_EVENT, AFTER_STOP_EVENT, BEFORE_DESTROY_EVENT, BEFORE_INIT_EVENT, BEFORE_START_EVENT, BEFORE_STOP_EVENT, CONFIGURE_START_EVENT, CONFIGURE_STOP_EVENT, PERIODIC_EVENT, START_EVENT, STOP_EVENT| Constructor and Description |
|---|
LockOutRealm() |
| Modifier and Type | Method and Description |
|---|---|
java.security.Principal |
authenticate(org.ietf.jgss.GSSContext gssContext,
boolean storeCreds)
Try to authenticate using a
GSSContext. |
java.security.Principal |
authenticate(org.ietf.jgss.GSSName gssName,
org.ietf.jgss.GSSCredential gssCredential)
Try to authenticate using a
GSSName. |
java.security.Principal |
authenticate(java.lang.String username,
java.lang.String credentials)
Try to authenticate using the specified username and
credentials.
|
java.security.Principal |
authenticate(java.lang.String username,
java.lang.String clientDigest,
java.lang.String nonce,
java.lang.String nc,
java.lang.String cnonce,
java.lang.String qop,
java.lang.String realmName,
java.lang.String digestA2,
java.lang.String algorithm)
Try to authenticate with the specified username, which
matches the digest calculated using the given parameters using the
method described in RFC 7616.
|
java.security.Principal |
authenticate(java.security.cert.X509Certificate[] certs)
Try to authenticate using a chain of
X509Certificates. |
int |
getCacheRemovalWarningTime()
Get the minimum period a failed authentication must remain in the cache to avoid generating a warning if it is
removed from the cache to make space for a new entry.
|
int |
getCacheSize()
Get the maximum number of users for which authentication failure will be kept in the cache.
|
int |
getFailureCount()
Get the number of failed authentication attempts required to lock the user account.
|
int |
getLockOutTime()
Get the period for which an account will be locked.
|
boolean |
isLocked(java.lang.String username) |
void |
setCacheRemovalWarningTime(int cacheRemovalWarningTime)
Set the minimum period a failed authentication must remain in the cache to avoid generating a warning if it is
removed from the cache to make space for a new entry.
|
void |
setCacheSize(int cacheSize)
Set the maximum number of users for which authentication failure will be kept in the cache.
|
void |
setFailureCount(int failureCount)
Set the number of failed authentication attempts required to lock the user account.
|
void |
setLockOutTime(int lockOutTime)
Set the period for which an account will be locked.
|
protected void |
startInternal()
Prepare for the beginning of active use of the public methods of this component and implement the requirements of
LifecycleBase.startInternal(). |
void |
unlock(java.lang.String username)
Unlock the specified username.
|
addRealm, authenticate, backgroundProcess, destroyInternal, getNestedRealms, getPassword, getPrincipal, getRealms, hasRole, isAvailable, setContainer, setCredentialHandler, stopInternaladdPropertyChangeListener, authenticate, findSecurityConstraints, getAllRolesMode, getContainer, getCredentialHandler, getDigest, getDigest, getDomainInternal, getObjectNameKeyProperties, getPrincipal, getPrincipal, getPrincipal, getRealmPath, getRealmSuffix, getRoles, getServer, getTransportGuaranteeRedirectStatus, getUserAttributes, getValidate, getX509UsernameRetrieverClassName, hasMessageDigest, hasResourcePermission, hasRoleInternal, hasUserDataPermission, initInternal, isStripRealmForGss, main, parseUserAttributes, removePropertyChangeListener, setAllRolesMode, setRealmPath, setStripRealmForGss, setTransportGuaranteeRedirectStatus, setUserAttributes, setValidate, setX509UsernameRetrieverClassName, toStringgetDomain, getObjectName, postDeregister, postRegister, preDeregister, preRegister, register, setDomain, unregister, unregisteraddLifecycleListener, destroy, findLifecycleListeners, fireLifecycleEvent, getState, getStateName, getThrowOnFailure, init, removeLifecycleListener, setState, setState, setThrowOnFailure, start, stopprotected int failureCount
protected int lockOutTime
protected int cacheSize
protected int cacheRemovalWarningTime
protected java.util.Map<java.lang.String,LockOutRealm.LockRecord> failedUsers
protected void startInternal()
throws LifecycleException
RealmBaseLifecycleBase.startInternal().startInternal in class CombinedRealmLifecycleException - if this component detects a fatal error that prevents this component from being
usedpublic java.security.Principal authenticate(java.lang.String username,
java.lang.String clientDigest,
java.lang.String nonce,
java.lang.String nc,
java.lang.String cnonce,
java.lang.String qop,
java.lang.String realmName,
java.lang.String digestA2,
java.lang.String algorithm)
Realm
The default implementation calls Realm.authenticate(String, String,
String, String, String, String, String, String) for backwards
compatibility which effectively forces the use of MD5 regardless of the
algorithm specified in the call to this method.
Implementations are expected to override the default implementation and take account of the algorithm parameter.
authenticate in interface Realmauthenticate in class CombinedRealmusername - Username of the Principal to look upclientDigest - Digest which has been submitted by the clientnonce - Unique (or supposedly unique) token which has been used
for this requestnc - the nonce countercnonce - the client chosen nonceqop - the "quality of protection" (nc and cnonce
will only be used, if qop is not null).realmName - Realm namedigestA2 - Second digest calculated as digest(Method + ":" + uri)algorithm - The message digest algorithm to usenull if there is none.public java.security.Principal authenticate(java.lang.String username,
java.lang.String credentials)
Realmauthenticate in interface Realmauthenticate in class CombinedRealmusername - Username of the Principal to look upcredentials - Password or other credentials to use in
authenticating this usernamenull if there is nonepublic java.security.Principal authenticate(java.security.cert.X509Certificate[] certs)
RealmX509Certificates.authenticate in interface Realmauthenticate in class CombinedRealmcerts - Array of client certificates, with the first one in
the array being the certificate of the client itself.null if there is nonepublic java.security.Principal authenticate(org.ietf.jgss.GSSContext gssContext,
boolean storeCreds)
RealmGSSContext.authenticate in interface Realmauthenticate in class CombinedRealmgssContext - The gssContext processed by the Authenticator.storeCreds - Should the realm attempt to store the delegated
credentials in the returned Principal?null if there is nonepublic java.security.Principal authenticate(org.ietf.jgss.GSSName gssName,
org.ietf.jgss.GSSCredential gssCredential)
RealmGSSName.
Note that this default method will be turned into an abstract one in
Tomcat 10.authenticate in interface Realmauthenticate in class CombinedRealmgssName - The GSSName of the principal to look upgssCredential - The GSSCredential of the principal, may be
nullnull if there is nonepublic void unlock(java.lang.String username)
username - The user to unlockpublic boolean isLocked(java.lang.String username)
public int getFailureCount()
public void setFailureCount(int failureCount)
failureCount - the failureCount to setpublic int getLockOutTime()
public void setLockOutTime(int lockOutTime)
lockOutTime - the lockOutTime to setpublic int getCacheSize()
public void setCacheSize(int cacheSize)
cacheSize - the cacheSize to setpublic int getCacheRemovalWarningTime()
public void setCacheRemovalWarningTime(int cacheRemovalWarningTime)
cacheRemovalWarningTime - the cacheRemovalWarningTime to setCopyright © 2000-2024 Apache Software Foundation.
Apache Tomcat, Tomcat, Apache, the Apache Tomcat logo and the Apache logo are either registered trademarks or trademarks of the Apache Software Foundation.