Tomcat 8.5 mapping ldap groups to security roles does not work

Viewed 144

I'm trying to map security-roles of an application to ldap groups in a tomcat 8.5.13. To test this, I'm trying the example protected tomcat app. From what I've found, I have to add a block like this to the WEB-INF/web.xml of the application:

    <!-- Security roles referenced by this web application -->
    <security-role>
      <role-name>role1</role-name>
    </security-role>
    <security-role>
      <role-name>tomcat</role-name>
    </security-role>
    <security-role-ref>
        <role-name>CN=LDAP_GROUP,OU=Groups,DC=<sub_dc>,DC=<dc>,DC=com</role-name>
        <role-link>tomcat</role-link>
    </security-role-ref>

"tomcat" and "role1" are configured as roles in a auth-constraint for the example app.

This is my JNDI config in $TOMCAT_HOME/conf/server.xml:

      <Realm className="org.apache.catalina.realm.LockOutRealm">
        <Realm className="org.apache.catalina.realm.UserDatabaseRealm"
               resourceName="UserDatabase"/>
        <Realm className="org.apache.catalina.realm.JNDIRealm"
             connectionURL="ldap://<ldap_host>:3268"
             connectionName="<ldap_bind_dn>"
             connectionPassword="<ldap_pw>"
             connectionTimeout="3000"
             referrals="follow"
             userBase="DC=<sub_dc>,DC=<dc>,DC=com"
             userSubtree="true"
             userSearch="(sAMAccountName={0})"
             userRoleName="memberOf"
             roleBase="DC=<sub_dc>,DC=<dc>,DC=com"
             roleSubtree="true"
             roleSearch="(uniqueMember={0})"
             roleName="cn"
             roleNested="true"
        />
      </Realm>

I see that all the ldap groups of the user including LDAP_GROUP mentioned in the security-role-ref above are found according to the log. However it seems the role reference is not used. Trying "http://:8080/examples/jsp/security/protected/index.jsp" gives:

org.apache.catalina.authenticator.AuthenticatorBase.invoke  Calling authenticate()
org.apache.catalina.authenticator.FormAuthenticator.doAuthenticate Restore request from session 'BB74A040FCCEEEDC150EC5671B6BF7B6'
org.apache.catalina.authenticator.AuthenticatorBase.register Authenticated 'ldap_user' with type 'FORM'
org.apache.catalina.authenticator.AuthenticatorBase.register Session ID changed on authentication from [BB74A040FCCEEEDC150EC5671B6BF7B6] to [A5735CBE706B62943EB9B29899C0CCCD]
org.apache.catalina.authenticator.FormAuthenticator.doAuthenticate Proceed to restored request
org.apache.catalina.authenticator.AuthenticatorBase.invoke  Calling accessControl()
org.apache.catalina.realm.RealmBase.hasResourcePermission   Checking roles GenericPrincipal[ldap_user(CN=LDAP_GROUP,OU=Groups,DC=<sub_dc>,DC=<dc>,DC=com,<many_more_ldap_group_DNs>,)]
org.apache.catalina.realm.RealmBase.hasRole Username ldap_user does NOT have role tomcat
org.apache.catalina.realm.RealmBase.hasResourcePermission No role found:  tomcat
org.apache.catalina.realm.RealmBase.hasRole Username ldap_user does NOT have role role1
org.apache.catalina.realm.RealmBase.hasResourcePermission No role found:  role1
org.apache.catalina.authenticator.AuthenticatorBase.invoke  Failed accessControl() test

I've tried defining and removing <role rolename="tomcat"/> in $TOMCAT_HOME/conf/tomcat-users.xml as well as defining the LDAP_GROUP without the distinguished name in the security-role-ref but that does not make a difference.

Any suggestions? Thank you in advance.

0 Answers
Related