In some ways, working with .NET code spoils you.  When working with ASP.NET apps which want to use Authorization information based upon the authenticated user’s PAC contents, it’s a simple call to IsInRole(). This uses the Privilege Attribute Certificate (PAC) in the Kerberos ticket to determine if a user is in a specific group for determining authorization.

You can find more information on the information in the PAC in Microsoft’s article:

This is a much more efficient way of determining authorization based upon group data than making LDAP calls to retrieve member lists.  I’ve worked with some applications that iterate through many LDAP calls just to determine if a user is in a specific group, which may not be reflective of groups across domain or forest boundaries.

Well, today,  someone asked if this was possible to have similar functionality, but in a JAVA application.   While in theory I was sure,  they also asked if I could provide some JAVA examples to be used on a Web server.  Fortunately,  Jens Bo Friis at AppliedCrypto.com has written a great article explaining the PAC, and how to use it several JAVA platforms to determine authorization information within the Kerberos ticket.

PAC (Privilege Attribute Certificate) in a Java Web Server World

Jens also has many useful articles for SPNEGO integration with Websphere, Weblogic, Tomcat and Apache which can be found at:

Hassle free single sign-on integrated with your enterprise windows domain

  • RE: JAVA of the PAC

    I tend to run into many JAVA coded applications which are coded simply for LDAP access, but do not utilize Active Directory as well as they could be.  Here are some resources JAVA developers can utilize to create more effective integrations.

  • RE: JAVA of the PAC
    I tend to run into many JAVA coded applications which are coded simply for LDAP access, but do not utilize Active Directory as well as they could be.  Here are some resources JAVA developers can utilize to create more effective integrations.

  • prada

    Here elaborates the matter not only extensively but also detailly .I support the
    write's unique point.It is useful and benefit to your daily life.You can go those
    sits to know more relate things.They are strongly recommended by friends.Personally
    I feel quite well.. http://www.prada-outlet-store.com