You can find more information on the information in the PAC in Microsoft’s article:
- Utilizing the Windows 2000 Authorization Data in Kerberos Tickets for Access Control to Resources
- [MS-PAC]: Privilege Attribute Certificate Data Structure
This is a much more efficient way of determining authorization based upon group data than making LDAP calls to retrieve member lists. I’ve worked with some applications that iterate through many LDAP calls just to determine if a user is in a specific group, which may not be reflective of groups across domain or forest boundaries.
Well, today, someone asked if this was possible to have similar functionality, but in a JAVA application. While in theory I was sure, they also asked if I could provide some JAVA examples to be used on a Web server. Fortunately, Jens Bo Friis at AppliedCrypto.com has written a great article explaining the PAC, and how to use it several JAVA platforms to determine authorization information within the Kerberos ticket.
PAC (Privilege Attribute Certificate) in a Java Web Server World
Jens also has many useful articles for SPNEGO integration with Websphere, Weblogic, Tomcat and Apache which can be found at:
Hassle free single sign-on integrated with your enterprise windows domain


Here elaborates the matter not only extensively but also detailly .I support the
write's unique point.It is useful and benefit to your daily life.You can go those
sits to know more relate things.They are strongly recommended by friends.Personally
I feel quite well.. http://www.prada-outlet-store.com
- spam
- offensive
- disagree
- off topic
Like