LoginException:登录失败:安全异常 [英] LoginException: Login failed: Security Exception

查看:1750
本文介绍了LoginException:登录失败:安全异常的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧!

问题描述

我试图用GlassFish v3.1.1 Build 12和JSF 2.1设置容器管理的安全性。由于某种原因,我不断收到以下异常,我无法登录。

 警告:WEB9102:Web Login Failed:com。 sun.enterprise.security.auth.login.common.LoginException:登录失败:安全异常
警告:异常
com.sun.enterprise.security.auth.login.common.LoginException:登录失败:安全性例外
at com.sun.enterprise.security.auth.login.LoginContextDriver.doPasswordLogin(LoginContextDriver.java:394)
at com.sun.enterprise.security.auth.login.LoginContextDriver.login(LoginContextDriver .java:240)
at com.sun.enterprise.security.auth.login.LoginContextDriver.login(LoginContextDriver.java:153)
at com.sun.web.security.RealmAdapter.authenticate(RealmAdapter .java:512)
at com.sun.web.security.RealmAdapter.authenticate(RealmAdapter.java:453)
at org.apache.catalina.connector.Request.login(Request.java:1932 )$ or $ $ b $ org.apache.catalina.connector.Request.login(Request.java:1895 )
at org.apache.catalina.connector.RequestFacade.login(RequestFacade.java:1146)
at com.perpro.controller.MemberBean.doNavigation(MemberBean.java:354)
at sun.reflect.NativeMethodAccessorImpl.invoke0(本地方法)
at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
at java.lang.reflect.Method.invoke(Method.java:597)
at com.sun.el.parser.AstValue.invoke(AstValue.java:234)
at com。 sun.el.MethodExpressionImpl.invoke(MethodExpressionImpl.java:297)
在org.jboss.weld.util.el.ForwardingMethodExpression.invoke(ForwardingMethodExpression.java:43)
在org.jboss.weld。 el.WeldMethodExpression.invoke(WeldMethodExpression.java:56)
at com.sun.faces.facelets.el.TagMethodExpression.invoke(TagMethodExpression.java:105)
at javax.faces.component.MethodBindingMethodExpressionAdapter。 invok e(MethodBindingMethodExpressionAdapter.java:88)
at com.sun.faces.application.ActionListenerImpl.processAction(ActionListenerImpl.java:102)
at javax.faces.component.UICommand.broadcast(UICommand.java: 315)
at javax.faces.component.UIViewRoot.broadcastEvents(UIViewRoot.java:794)
at javax.faces.component.UIViewRoot.processApplication(UIViewRoot.java:1259)
at com .sun.faces.lifecycle.InvokeApplicationPhase.execute(InvokeApplicationPhase.java:81)
at com.sun.faces.lifecycle.Phase.doPhase(Phase.java:101)
at com.sun.faces .lifecycle.LifecycleImpl.execute(LifecycleImpl.java:118)
在javax.faces.webapp.FacesServlet.service(FacesServlet.java:593)
在org.apache.catalina.core.StandardWrapper.service (StandardWrapper.java:1539)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:343)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChai n.java:217)
处org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java org.primefaces.webapp.filter.FileUploadFilter.doFilter(FileUploadFilter.java:79)
:在org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:217 256)

在org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:279)$ b在org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:175)
$ b在org.apache.catalina.core.StandardPipeline.doInvoke(StandardPipeline.java:655)
。在组织.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:595)
at com.sun.enterprise.web.WebPipeline.invoke(WebPipeline.java:98)
at com.sun.enterprise .web.PESessionLockingStandardPipeline.invoke(PESessionLockingStandardPipeline.java:91)
在org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:162)
在org.apache.catalina .connector.CoyoteAdapter.doService(CoyoteAdapter.java:330)
at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:231)
at com.sun.enterprise.v3.services .impl.ContainerMapper.service(ContainerMapper.java:174)
at com.sun.grizzly.http.ProcessorTask.invokeAdapter(ProcessorTask.java:828)
at com.sun.grizzly.http.ProcessorTask .doProcess(ProcessorTask.java:725)
在com.sun.grizzly.http.ProcessorTask.process(ProcessorTask.java:1019)
在com.sun.grizzly.http.DefaultProtocolFilter.execute(DefaultProtocolFilter .java:225)
at com.sun.grizzly.DefaultProtocolChain.executeProtocolFilter(DefaultProtocolChain.java:137)
at com.sun.grizzly.DefaultProtocolChain.execute(DefaultProtocolChain.java:104)
。在com.sun.grizzly.DefaultProtocolChain.execute(DefaultProtocolChain.java:90)
在com.sun.grizzly.http.HttpProtocolChain.execute(HttpProtocolChain.java:79)
在的com.sun。 grizzly.ProtocolChainContextTas k.doCall(ProtocolChainContextTask.java:54)
在com.sun.grizzly.SelectionKeyContextTask.call(SelectionKeyContextTask.java:59)
在com.sun.grizzly.ContextTask.run(ContextTask.java: 71)
at com.sun.grizzly.util.AbstractThreadPool $ Worker.doWork(AbstractThreadPool.java:532)
at com.sun.grizzly.util.AbstractThreadPool $ Worker.run(AbstractThreadPool.java: 513)
在java.lang.Thread.run(Thread.java:662)
导致:javax.security.auth.login.LoginException:安全异常$ b $在javax.security.auth .login.LoginContext.invoke(LoginContext.java:856)
位于javax.security.auth.login.LoginContext.access $ 000(LoginContext.java:186)
位于javax.security.auth.login。在java.security.AccessController.doPrivileged(本机方法)
在javax.security.auth.login.LoginContext.invokePriv(LoginContext.java:680)LoginContext的$ 4.run(LoginContext.java:683)

位于javax.security.auth.login.LoginContext.login(LoginContext.java:579)
在com.sun.enterprise.security.auth.login.LoginContextDriver.doPasswordLogin(LoginContextDriver.java:382)
... 56 more
由于:java.lang.SecurityException $ b $在javax .security.auth.login.LoginContext.invoke(LoginContext.java:857)
... 62 more

SEVERE:javax.servlet.ServletException:尝试对用户进行身份验证时抛出异常:admin
at org.apache.catalina.connector.Request.login(Request.java:1964)
at org.apache.catalina.connector.Request.login(Request.java:1895)
at org.apache.catalina.connector.RequestFacade.login(RequestFacade.java:1146)
at com.perpro.controller.MemberBean.doNavigation(MemberBean.java:354)
at sun.reflect .NativeMethodAccessorImpl.invoke0(本地方法)
at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
在java.lang.reflect.M ethod.invoke(Method.java:597)
at com.sun.el.parser.AstValue.invoke(AstValue.java:234)
at com.sun.el.MethodExpressionImpl.invoke(MethodExpressionImpl。 Java的:297),美元,org.jboss.weld.util.el.ForwardingMethodExpression.invoke(ForwardingMethodExpression.java:43 b $ b)
在org.jboss.weld.el.WeldMethodExpression.invoke(WeldMethodExpression.java: 56)
。在com.sun.faces.facelets.el.TagMethodExpression.invoke(TagMethodExpression.java:105)
。在javax.faces.component.MethodBindingMethodExpressionAdapter.invoke(MethodBindingMethodExpressionAdapter.java:88)
在com.sun.faces.application.ActionListenerImpl.processAction(ActionListenerImpl.java:102)
在javax.faces.component.UICommand.broadcast(UICommand.java:315)
在javax.faces .component.UIViewRoot.broadcastEvents(UIViewRoot.java:794)
at javax.faces.component.UIViewRoot.processApplication(UIViewRoot.java:1259)
at com.sun.faces.lifecycle.InvokeApplicationPhase.execute (在vokeApplicationPhase.java:81)
at com.sun.faces.lifecycle.Phase.doPhase(Phase.java:101)
at com.sun.faces.lifecycle.LifecycleImpl.execute(LifecycleImpl.java: 118)
在javax.faces.webapp.FacesServlet.service(FacesServlet.java:593)
在org.apache.catalina.core.StandardWrapper.service(StandardWrapper.java:1539)
在org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:343)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:217)
at org.primefaces .webapp.filter.FileUploadFilter.doFilter(FileUploadFilter.java:79)
在org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:256)
在org.apache.catalina.core .ApplicationFilterChain.doFilter(ApplicationFilterChain.java:217)
在org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:279)
在org.apache.catalina.core.StandardC ontextValve.invoke(StandardContextValve.java:175)
at org.apache.catalina.core.StandardPipeline.doInvoke(StandardPipeline.java:655)
at org.apache.catalina.core.StandardPipeline.invoke( StandardPipeline.java:595)
在com.sun.enterprise.web.WebPipeline.invoke(WebPipeline.java:98)
在com.sun.enterprise.web.PESessionLockingStandardPipeline.invoke(PESessionLockingStandardPipeline.java: 91)
。在org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:162)
。在org.apache.catalina.connector.CoyoteAdapter.doService(CoyoteAdapter.java:330)
在org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:231)
在com.sun.enterprise.v3.services.impl.ContainerMapper.service(ContainerMapper.java:174)
at com.sun.grizzly.http.ProcessorTask.invokeAdapter(ProcessorTask.java:828)
at com.sun.grizzly.http.ProcessorTask.doProcess(ProcessorTask.java:725)
at com .sun.grizzly.http.ProcessorTask.p rocess(ProcessorTask.java:1019)
在com.sun.grizzly.http.DefaultProtocolFilter.execute(DefaultProtocolFilter.java:225)
在com.sun.grizzly.DefaultProtocolChain.executeProtocolFilter(DefaultProtocolChain.java: 137)
at com.sun.grizzly.DefaultProtocolChain.execute(DefaultProtocolChain.java:104)
at com.sun.grizzly.DefaultProtocolChain.execute(DefaultProtocolChain.java:90)
at com .sun.grizzly.http.HttpProtocolChain.execute(HttpProtocolChain.java:79)在com.sun.grizzly.ProtocolChainContextTask.doCall(ProtocolChainContextTask.java:54)

在com.sun.grizzly.SelectionKeyContextTask .call(SelectionKeyContextTask.java:59)
at com.sun.grizzly.ContextTask.run(ContextTask.java:71)
at com.sun.grizzly.util.AbstractThreadPool $ Worker.doWork(AbstractThreadPool .java:532)
at com.sun.grizzly.util.AbstractThreadPool $ Worker.run(AbstractThreadPool.java:513)$ b $ at java.lang.Thread.run(Thread.java:662)
由:javax.se引起rvlet.ServletException:尝试验证用户时失败登录:admin $ b $ at org.apache.catalina.connector.Request.login(Request.java:1935)
... 51 more

web.xml:

 <安全约束> 
< display-name> UserConstraints< / display-name>
< web-resource-collection>
< web-resource-name>页面< / web-resource-name>
< description />
< url-pattern> /home.jsf< / url-pattern>
< / web-resource-collection>
< auth-constraint>
<角色名称> USER< /角色名称>
<角色名称>管理员< /角色名称>
< / auth-constraint>
< / security-constraint>
< security-constraint>
< display-name> AdminConstraints< / display-name>
< web-resource-collection>
< web-resource-name>页面< / web-resource-name>
< description />
< url-pattern> /home.jsf< / url-pattern>
< / web-resource-collection>
< auth-constraint>
<角色名称>管理员< /角色名称>
< / auth-constraint>
< / security-constraint>
< login-config>
< auth-method> FORM< / auth-method>
< realm-name> PerProUserAuth< / realm-name>
< form-login-config>
< form-login-page> /index.jsf< / form-login-page>
< form-error-page> /index.jsf?error = true< / form-error-page>
< / form-login-config>
< / login-config>
< security-role>
< description />
<角色名称> USER< /角色名称>
< / security-role>
< security-role>
< description />
<角色名称>管理员< /角色名称>
< / security-role>

glassfish-web.xml:
$ b

 < security-role-mapping> 
<角色名称>管理员< /角色名称>
< group-name>内部< /组名>
< group-name>外部< /组名>
< / security-role-mapping>
< security-role-mapping>
<角色名称> USER< /角色名称>
< group-name>内部< /组名>
< group-name>外部< /组名>
< / security-role-mapping>

GlassFish管理控制台领域设置:

领域名称:PerProUserAuth

类名称:com.sun.enterprise.security.auth.realm.jdbc。 JDBCRealm

JAAS上下文:jdbcRealm
<
JNDI:表格:用户名称
用户名称栏: mem_id

密码栏:密码
组表:用户

组名称列: mem_status

摘要算法: / strong> SHA-256

编码: Base64


最后,我的USER表有(:管理员明文):JIkcSMs4aijfwzpVjZ0MbzgWmoieGm7fxF0pTmH +崔=

解决方案
管理员 和密码是SHA-256底座64编码为一个mem_id

只是一个猜测:我会尝试 jGl25bVBBBW96Qi9Te4V37Fnqchz / Eu4qB9vKrRIqRg = 作为密码的散列 admin

  final MessageDigest messageDigest = java.security.MessageDigest。 
getInstance(SHA-256);
final byte bin [] = messageDigest.digest((admin)。getBytes());
System.out.println(Base64.encodeBase64String(bin));

(Base64 from




另一个想法:用hash 8c6976e5b5410415bde908bd4dee15dfb167a9c873fc4bb8a81f6f2ab448a918 (密码: admin )和十六进制编码。它是由以下内容生成的:

  final String hash = DigestUtils.sha256Hex(admin); 
System.out.println(hash);


I am attempting to setup container managed security with GlassFish v3.1.1 Build 12 and JSF 2.1. I keep getting the following exception for some reason and I am unable to login.

WARNING: WEB9102: Web Login Failed: com.sun.enterprise.security.auth.login.common.LoginException: Login failed: Security Exception
WARNING: Exception
com.sun.enterprise.security.auth.login.common.LoginException: Login failed: Security Exception
    at com.sun.enterprise.security.auth.login.LoginContextDriver.doPasswordLogin(LoginContextDriver.java:394)
    at com.sun.enterprise.security.auth.login.LoginContextDriver.login(LoginContextDriver.java:240)
    at com.sun.enterprise.security.auth.login.LoginContextDriver.login(LoginContextDriver.java:153)
    at com.sun.web.security.RealmAdapter.authenticate(RealmAdapter.java:512)
    at com.sun.web.security.RealmAdapter.authenticate(RealmAdapter.java:453)
    at org.apache.catalina.connector.Request.login(Request.java:1932)
    at org.apache.catalina.connector.Request.login(Request.java:1895)
    at org.apache.catalina.connector.RequestFacade.login(RequestFacade.java:1146)
    at com.perpro.controller.MemberBean.doNavigation(MemberBean.java:354)
    at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
    at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
    at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
    at java.lang.reflect.Method.invoke(Method.java:597)
    at com.sun.el.parser.AstValue.invoke(AstValue.java:234)
    at com.sun.el.MethodExpressionImpl.invoke(MethodExpressionImpl.java:297)
    at org.jboss.weld.util.el.ForwardingMethodExpression.invoke(ForwardingMethodExpression.java:43)
    at org.jboss.weld.el.WeldMethodExpression.invoke(WeldMethodExpression.java:56)
    at com.sun.faces.facelets.el.TagMethodExpression.invoke(TagMethodExpression.java:105)
    at javax.faces.component.MethodBindingMethodExpressionAdapter.invoke(MethodBindingMethodExpressionAdapter.java:88)
    at com.sun.faces.application.ActionListenerImpl.processAction(ActionListenerImpl.java:102)
    at javax.faces.component.UICommand.broadcast(UICommand.java:315)
    at javax.faces.component.UIViewRoot.broadcastEvents(UIViewRoot.java:794)
    at javax.faces.component.UIViewRoot.processApplication(UIViewRoot.java:1259)
    at com.sun.faces.lifecycle.InvokeApplicationPhase.execute(InvokeApplicationPhase.java:81)
    at com.sun.faces.lifecycle.Phase.doPhase(Phase.java:101)
    at com.sun.faces.lifecycle.LifecycleImpl.execute(LifecycleImpl.java:118)
    at javax.faces.webapp.FacesServlet.service(FacesServlet.java:593)
    at org.apache.catalina.core.StandardWrapper.service(StandardWrapper.java:1539)
    at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:343)
    at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:217)
    at org.primefaces.webapp.filter.FileUploadFilter.doFilter(FileUploadFilter.java:79)
    at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:256)
    at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:217)
    at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:279)
    at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:175)
    at org.apache.catalina.core.StandardPipeline.doInvoke(StandardPipeline.java:655)
    at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:595)
    at com.sun.enterprise.web.WebPipeline.invoke(WebPipeline.java:98)
    at com.sun.enterprise.web.PESessionLockingStandardPipeline.invoke(PESessionLockingStandardPipeline.java:91)
    at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:162)
    at org.apache.catalina.connector.CoyoteAdapter.doService(CoyoteAdapter.java:330)
    at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:231)
    at com.sun.enterprise.v3.services.impl.ContainerMapper.service(ContainerMapper.java:174)
    at com.sun.grizzly.http.ProcessorTask.invokeAdapter(ProcessorTask.java:828)
    at com.sun.grizzly.http.ProcessorTask.doProcess(ProcessorTask.java:725)
    at com.sun.grizzly.http.ProcessorTask.process(ProcessorTask.java:1019)
    at com.sun.grizzly.http.DefaultProtocolFilter.execute(DefaultProtocolFilter.java:225)
    at com.sun.grizzly.DefaultProtocolChain.executeProtocolFilter(DefaultProtocolChain.java:137)
    at com.sun.grizzly.DefaultProtocolChain.execute(DefaultProtocolChain.java:104)
    at com.sun.grizzly.DefaultProtocolChain.execute(DefaultProtocolChain.java:90)
    at com.sun.grizzly.http.HttpProtocolChain.execute(HttpProtocolChain.java:79)
    at com.sun.grizzly.ProtocolChainContextTask.doCall(ProtocolChainContextTask.java:54)
    at com.sun.grizzly.SelectionKeyContextTask.call(SelectionKeyContextTask.java:59)
    at com.sun.grizzly.ContextTask.run(ContextTask.java:71)
    at com.sun.grizzly.util.AbstractThreadPool$Worker.doWork(AbstractThreadPool.java:532)
    at com.sun.grizzly.util.AbstractThreadPool$Worker.run(AbstractThreadPool.java:513)
    at java.lang.Thread.run(Thread.java:662)
Caused by: javax.security.auth.login.LoginException: Security Exception
    at javax.security.auth.login.LoginContext.invoke(LoginContext.java:856)
    at javax.security.auth.login.LoginContext.access$000(LoginContext.java:186)
    at javax.security.auth.login.LoginContext$4.run(LoginContext.java:683)
    at java.security.AccessController.doPrivileged(Native Method)
    at javax.security.auth.login.LoginContext.invokePriv(LoginContext.java:680)
    at javax.security.auth.login.LoginContext.login(LoginContext.java:579)
    at com.sun.enterprise.security.auth.login.LoginContextDriver.doPasswordLogin(LoginContextDriver.java:382)
    ... 56 more
Caused by: java.lang.SecurityException
    at javax.security.auth.login.LoginContext.invoke(LoginContext.java:857)
    ... 62 more

SEVERE: javax.servlet.ServletException: Exception thrown while attempting to authenticate for user: admin
    at org.apache.catalina.connector.Request.login(Request.java:1964)
    at org.apache.catalina.connector.Request.login(Request.java:1895)
    at org.apache.catalina.connector.RequestFacade.login(RequestFacade.java:1146)
    at com.perpro.controller.MemberBean.doNavigation(MemberBean.java:354)
    at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
    at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
    at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
    at java.lang.reflect.Method.invoke(Method.java:597)
    at com.sun.el.parser.AstValue.invoke(AstValue.java:234)
    at com.sun.el.MethodExpressionImpl.invoke(MethodExpressionImpl.java:297)
    at org.jboss.weld.util.el.ForwardingMethodExpression.invoke(ForwardingMethodExpression.java:43)
    at org.jboss.weld.el.WeldMethodExpression.invoke(WeldMethodExpression.java:56)
    at com.sun.faces.facelets.el.TagMethodExpression.invoke(TagMethodExpression.java:105)
    at javax.faces.component.MethodBindingMethodExpressionAdapter.invoke(MethodBindingMethodExpressionAdapter.java:88)
    at com.sun.faces.application.ActionListenerImpl.processAction(ActionListenerImpl.java:102)
    at javax.faces.component.UICommand.broadcast(UICommand.java:315)
    at javax.faces.component.UIViewRoot.broadcastEvents(UIViewRoot.java:794)
    at javax.faces.component.UIViewRoot.processApplication(UIViewRoot.java:1259)
    at com.sun.faces.lifecycle.InvokeApplicationPhase.execute(InvokeApplicationPhase.java:81)
    at com.sun.faces.lifecycle.Phase.doPhase(Phase.java:101)
    at com.sun.faces.lifecycle.LifecycleImpl.execute(LifecycleImpl.java:118)
    at javax.faces.webapp.FacesServlet.service(FacesServlet.java:593)
    at org.apache.catalina.core.StandardWrapper.service(StandardWrapper.java:1539)
    at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:343)
    at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:217)
    at org.primefaces.webapp.filter.FileUploadFilter.doFilter(FileUploadFilter.java:79)
    at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:256)
    at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:217)
    at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:279)
    at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:175)
    at org.apache.catalina.core.StandardPipeline.doInvoke(StandardPipeline.java:655)
    at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:595)
    at com.sun.enterprise.web.WebPipeline.invoke(WebPipeline.java:98)
    at com.sun.enterprise.web.PESessionLockingStandardPipeline.invoke(PESessionLockingStandardPipeline.java:91)
    at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:162)
    at org.apache.catalina.connector.CoyoteAdapter.doService(CoyoteAdapter.java:330)
    at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:231)
    at com.sun.enterprise.v3.services.impl.ContainerMapper.service(ContainerMapper.java:174)
    at com.sun.grizzly.http.ProcessorTask.invokeAdapter(ProcessorTask.java:828)
    at com.sun.grizzly.http.ProcessorTask.doProcess(ProcessorTask.java:725)
    at com.sun.grizzly.http.ProcessorTask.process(ProcessorTask.java:1019)
    at com.sun.grizzly.http.DefaultProtocolFilter.execute(DefaultProtocolFilter.java:225)
    at com.sun.grizzly.DefaultProtocolChain.executeProtocolFilter(DefaultProtocolChain.java:137)
    at com.sun.grizzly.DefaultProtocolChain.execute(DefaultProtocolChain.java:104)
    at com.sun.grizzly.DefaultProtocolChain.execute(DefaultProtocolChain.java:90)
    at com.sun.grizzly.http.HttpProtocolChain.execute(HttpProtocolChain.java:79)
    at com.sun.grizzly.ProtocolChainContextTask.doCall(ProtocolChainContextTask.java:54)
    at com.sun.grizzly.SelectionKeyContextTask.call(SelectionKeyContextTask.java:59)
    at com.sun.grizzly.ContextTask.run(ContextTask.java:71)
    at com.sun.grizzly.util.AbstractThreadPool$Worker.doWork(AbstractThreadPool.java:532)
    at com.sun.grizzly.util.AbstractThreadPool$Worker.run(AbstractThreadPool.java:513)
    at java.lang.Thread.run(Thread.java:662)
Caused by: javax.servlet.ServletException: Failed login while attempting to authenticate user: admin
    at org.apache.catalina.connector.Request.login(Request.java:1935)
    ... 51 more

web.xml:

<security-constraint>
        <display-name>UserConstraints</display-name>
        <web-resource-collection>
            <web-resource-name>Pages</web-resource-name>
            <description/>
            <url-pattern>/home.jsf</url-pattern>
        </web-resource-collection>
        <auth-constraint>
            <role-name>USER</role-name>
            <role-name>ADMINISTRATOR</role-name>
        </auth-constraint>
    </security-constraint>
    <security-constraint>
        <display-name>AdminConstraints</display-name>
        <web-resource-collection>
            <web-resource-name>Pages</web-resource-name>
            <description/>
            <url-pattern>/home.jsf</url-pattern>
        </web-resource-collection>
        <auth-constraint>
            <role-name>ADMINISTRATOR</role-name>
        </auth-constraint>
    </security-constraint>
    <login-config>
        <auth-method>FORM</auth-method>
        <realm-name>PerProUserAuth</realm-name>
        <form-login-config>
            <form-login-page>/index.jsf</form-login-page>
            <form-error-page>/index.jsf?error=true</form-error-page>
        </form-login-config>
    </login-config>
    <security-role>
        <description/>
        <role-name>USER</role-name>
    </security-role>
    <security-role>
        <description/>
        <role-name>ADMINISTRATOR</role-name>
    </security-role>

glassfish-web.xml:

<security-role-mapping>
    <role-name>ADMINISTRATOR</role-name>
    <group-name>Internal</group-name>
    <group-name>External</group-name>
  </security-role-mapping>
  <security-role-mapping>
    <role-name>USER</role-name>
    <group-name>Internal</group-name>
    <group-name>External</group-name>
  </security-role-mapping>

GlassFish Admin Console Realm setup:

Realm Name: PerProUserAuth
Class Name: com.sun.enterprise.security.auth.realm.jdbc.JDBCRealm
JAAS Context: jdbcRealm
JNDI: MyDS
User Table: User
User Name Column: mem_id
Password Column: password
Group Table: User
Group Name Column: mem_status
Digest Algorithm: SHA-256
Encoding: Base64

And finally, my USER table has a mem_id of "admin" and a password that is SHA-256 base 64 encoded as (plaintext:admin): JIkcSMs4aijfwzpVjZ0MbzgWmoieGm7fxF0pTmH+cUI=

解决方案

Just a guess: I'd try with jGl25bVBBBW96Qi9Te4V37Fnqchz/Eu4qB9vKrRIqRg= as a hash for password admin.

final MessageDigest messageDigest = java.security.MessageDigest.
        getInstance("SHA-256");
final byte bin[] = messageDigest.digest(("admin").getBytes());
System.out.println(Base64.encodeBase64String(bin));

(Base64 from Apache Commons Codec)


Another idea: Try with hash 8c6976e5b5410415bde908bd4dee15dfb167a9c873fc4bb8a81f6f2ab448a918 (password: admin) and HEX encoding. It was generated with:

final String hash = DigestUtils.sha256Hex("admin");
System.out.println(hash);

这篇关于LoginException:登录失败:安全异常的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持IT屋!

查看全文
登录 关闭
扫码关注1秒登录
发送“验证码”获取 | 15天全站免登陆