Passing 'password expiration' information from Wildfly Server authentication module to remote EJB client

Viewed 379

We have a Wildfly 10 JEE application and a java fat client that uses remote EJ calls to communicate with the server. Authentication is done using a custom login module in the wildfly server.

Now we have the requirement to enhance this login module with the concept of a password expiration. Whenever a password expires the user has to change its password during the login process. The login module uses JAAS callbacks and the JAAS callback handler. As far as I've understood we could use the javax.security.auth.callback.TextInputCallback in our LoginModule to request the new password from the user while performing the login.

How does this integrate with remoting. How does our fat client receive the TextInputCallback to provide the requested input? I guess we have to register a custom CallbackHandler on client side that processes the callbacks but I have not found any documentation on how to do this with Wildfly. Can anybody give me a hint on such documentation or a sample on how to solve this problem?

1 Answers
Related