This package presents a framework that allows application developers to make use of security services like authentication, data integrity and data confidentiality from a variety of underlying security mechanisms like Kerberos, using a unified API.
This interface encapsulates the GSS-API security context and provides the security services that are available over the context.
This interface encapsulates the GSS-API credentials for an entity.
This interface encapsulates a single GSS-API principal entity.
This class encapsulates the concept of caller-provided channel binding information.
This class serves as a factory for other important GSS-API classes and also provides information about the mechanisms that are supported.
This is a utility class used within the per-message GSSContext methods to convey per-message properties.
This class represents Universal Object Identifiers (Oids) and their associated operations.
This exception is thrown whenever a GSS-API error occurs, including any mechanism specific error.
This package presents a framework that allows application developers to make use of security services like authentication, data integrity and data confidentiality from a variety of underlying security mechanisms like Kerberos, using a unified API. The security mechanisms that an application can chose to use are identified with unique object identifiers. One example of such a mechanism is the Kerberos v5 GSS-API mechanism (object identifier 1.2.840.113518.104.22.168). This mechanism is available through the default instance of the GSSManager class.
An application starts out by instantiating a
GSSManager which then serves as a factory for a security context. An application can use specific principal names and credentials that are also created using the GSSManager; or it can instantiate a context with system defaults. It then goes through a context establishment loop. Once a context is established with the peer, authentication is complete. Data protection such as integrity and confidentiality can then be obtained from this context.
The GSS-API does not perform any communication with the peer. It merely produces tokens that the application must somehow transport to the other end.
Subjectin the current access control context. The Kerberos v5 mechanism will search for the required INITIATE and ACCEPT credentials (
KerberosKey) in the private credential set where as some other mechanism might look in the public set or in both. If the desired credential is not present in the appropriate sets of the current Subject, the GSS-API call must fail.
This model has the advantage that credential management is simple and predictable from the applications point of view. An application, given the right permissions, can purge the credentials in the Subject or renew them using standard Java API's. If it purged the credentials, it would be sure that the JGSS mechanism would fail, or if it renewed a time based credential it would be sure that a JGSS mechanism would succeed.
This model does require that a
JAAS login be performed in order to authenticate and populate a Subject that the JGSS mechanism can later utilize. However, applications have the ability to relax this restriction by means of a system property:
javax.security.auth.useSubjectCredsOnly. By default this system property will be assumed to be
true (even when it is unset) indicating that providers must only use the credentials that are present in the current Subject. However, if this property is explicitly set to false by the application, then it indicates that the provider is free to use any credentials cache of its choice. Such a credential cache might be a disk cache, an in-memory cache, or even just the current Subject itself.
For an online tutorial on using Java GSS-API, please see Introduction to JAAS and Java GSS-API.
© 1993–2017, Oracle and/or its affiliates. All rights reserved.
Documentation extracted from Debian's OpenJDK Development Kit package.
Licensed under the GNU General Public License, version 2, with the Classpath Exception.
Various third party code in OpenJDK is licensed under different licenses (see Debian package).
Java and OpenJDK are trademarks or registered trademarks of Oracle and/or its affiliates.