Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Generate password for jsf client state encryption per VM #102

Closed
yurem opened this issue Dec 1, 2015 · 10 comments
Closed

Generate password for jsf client state encryption per VM #102

yurem opened this issue Dec 1, 2015 · 10 comments

Comments

@yurem
Copy link
Contributor

yurem commented Dec 1, 2015

We need to generate password in next section per VM:
7641eb8

@yurem
Copy link
Contributor Author

yurem commented Dec 1, 2015

All our oxAuth pages contains one hidden property. Example:
<input type="hidden" name="javax.faces.ViewState" id="javax.faces.ViewState" value="H4sIAAAAAAAAAM1aWWwcSRkuj+3YcSLiHJsD5XDiEMfJZDz3kWvjI46HjB2v7dwsTk9PzUxne7o73TWecaysdh92keAB0AISUhArwRsb8bASDzzArnhYCWlBRIIHnhZeAIljhRZxSBxV1cd091TP6SzbktvdPVV//fX9//fXX8dbfwL9ZRXsvpu5z61xAZGTCoFr2fuQR+
...

I think I find good answer: http://stackoverflow.com/questions/28231372/com-sun-faces-clientstatesavingpassword-recommendations-for-actual-password

In our case we uses: jsf-impl 1.2.12. I decompiled it and find inside: com.sun.faces.renderkit.ResponseStateManagerImpl
private void init()
{
...
String pass = webConfig.getEnvironmentEntry(com.sun.faces.config.WebConfiguration.WebEnvironmentEntry.ClientStateSavingPassword);
if(pass != null)
guard = new ByteArrayGuard(pass);

Hence it really uses encryption for javax.faces.ViewState if there next section in web.xml: 7641eb8

@yurem
Copy link
Contributor Author

yurem commented Dec 1, 2015

But according to commons-collections 3.2.2 release notes it do secure serialization now. Hence web.xml env property "ClientStateSavingPassword" probably not needed.

We need to make sure that jsf 1.2.12 do secure serialization with commons-collections 3.2.2. if yes we can remove env section from web.xml

@yuriyz
Copy link
Contributor

yuriyz commented Dec 1, 2015

See line 169 of ResponseStateManagerImpl. I assume we always need the password otherwise we will get simple input stream instead of encrypted one. (guard will be null if password is not specified in web.xml)

                if (guard != null) {
                    ois = serialProvider.createObjectInputStream(new CipherInputStream(bis, guard.getDecryptionCipher()));
                } else {
                    ois = serialProvider.createObjectInputStream(bis);
                }

@yurem
Copy link
Contributor Author

yurem commented Dec 1, 2015

yes, according to this example we have to set password

package org.xdi.oxauth.dev;

import java.io.File;
import java.io.IOException;
import java.util.Arrays;
import java.util.zip.GZIPInputStream;

import javax.crypto.CipherInputStream;

import org.apache.commons.io.FileUtils;

public class TestViewState {

private static void decode(String host, String viewString) throws IOException, ClassNotFoundException {
    try {
        GZIPInputStream is = new GZIPInputStream(new com.sun.faces.io.Base64InputStream(viewString));
        com.sun.faces.renderkit.ApplicationObjectInputStream objectInputStream = new com.sun.faces.renderkit.ApplicationObjectInputStream(is);
        Object res = objectInputStream.readObject();
        System.out.println(host + " : " + Arrays.toString((Object[]) res));
    } catch (java.io.StreamCorruptedException ex) {
        // Encrypted stream
        com.sun.faces.renderkit.ByteArrayGuard guard = new com.sun.faces.renderkit.ByteArrayGuard("1234567890");
        GZIPInputStream is = new GZIPInputStream(new com.sun.faces.io.Base64InputStream(viewString));
        com.sun.faces.renderkit.ApplicationObjectInputStream objectInputStream = new com.sun.faces.renderkit.ApplicationObjectInputStream(new CipherInputStream(is, guard.getDecryptionCipher()));
        Object res = objectInputStream.readObject();
        System.out.println(host + " encrypted : " + Arrays.toString((Object[]) res));
    }
}

public static void main(String[] args) throws IOException, ClassNotFoundException {
    decode("ce-release", "H4sIAAAAAAAAAM1aWWwcSRkuj+PYcSLiHJsD5XDsEOeYjOc+7GQ3PmJ72LGTtR0nm7A4PT3lmXZ6ujvdNZ7xWlntPrBI8ABoAQkpiEXwxkY8rMQDD7ArHlZCCohI8MDTwgsgcazQIg6Jo6r6mO6e6jmdZVtyu7un6q+/vv///vrreOtPoKekggN3MuvcBhcQOSkfuJZdhzwa//LPbn1rQDsn+gCoKACAk5oKIrxcDGglKbDG8VALcIoiCjyHBFkKLCEOwXlO4vJQTRcV8fSyCuGCnIMfrv3wR4+Csz/eQ+SUzwJyDZLWKoYULFORJSihwI30igDLi7KMcFntPngF+MpxWuEcu0IBFcXAHL5dKyGlhJZhBYGe9VUhFzGrJ2j1kQbV56GmYcU10Fc0nsz6UVp/uEH9GVktgl2inBck8mhvvBucl9V8YD0ra1pAg1wxUBJYIpble1DSlU/a+97dsO/XOQmKs6pcUvTqKXvzPa1At5NUD4XszfeAs02pPy1sGNUt6FO4ei+40KD5WZVTCgKfLmLUDQnRDjsQd3WgOfyEnFHdgj+Jq/eD8001n+GyUDQEpJwCGrWflkz1+0oaVCWuCO0A9LcMQDjYYQ/ClguMNSWA9mAJ8irEfVA4TSvLaq7DPoQ77YPlhzNUQLSBgCUo4qg3Kcsi5KSpAuTvZeUK6FdhERazUJ3v1CbRjlgVjtubP9h688nO6keCHakfCdubP9x689EO61vwPUfV9zeoPyUXi5yUmywhJEtgNw3s+ospZ5zKudgUDDMqly/iL7ou0aBdBmhPRsyOx7GW8YgmOqyfqpRIfXL5rKc+62kXzhX20YyihAQsgtMK85zS0/vrd39y6O4vuoFvBvSLMpeb4Xgkq2mwCxVUqBVkMVdRnrtCRews9xGR+K8LgbALo+sTs1dPu77pytP7dTKCq+AEs8SMWWLyB5l3Ku/dzftAz21wlJelDahqNJlJaxlZyi+WJEmQ8hnwCcdvOQT202xplGRLo0tIxYXGM2CvgmWuiXJ5Si5JCKoIHLAVS+NPODPC5faY5RZwoCeAncuAAesbTpis7zjtUvBVwX8WnjRDM6LU40H11V8+/NeffaDrNujZ4MQSrChd1LB+QOscqNpgQlW5zYygocprT45/4z3um92gKw12aMLLkKZ3XeUd5E4qj2Az988tz2dWJyeW0lMI7BmlDAhUiENgsQNVsRmZ50T4yj/23X0Y/Ocfu8HONOgrYHPzuCMZ0MsTLNRNo5v92IGgpGEUNeNLH+lPCXfeeN+p8aqgIOOtd4NTBU5CBhr/xRfODMlbDAEflOgTvVWcABlo7//tm9/9+2ufT/pIVw2ATO1puYUSie2vv/W147u/+v4XzUw3hgG3XHkHw9F7radum8uTp0/VeK8PgSP2rFmESAvMTyw+v5qexqNlIhXMxUIwySo1cf16Jn11GndttOY3AafYgWm4xpVENKN/PD2B0/FNmkfOPfz59Lj09Tf1nPsiGB69eXXyYnphZlSQeBF75KZcQqMIYiE4a9ftio3/wmdf//bjip3arqmB4eyPnqz87g/Ht2ZNwDBDdXStml1Y6TPsoEInCnOY6lBd4jCtXvzp25ffePh43gd8GbCLF3H6YGNGv4bL5GgdBA7phBLk0SWIHUMUXuayIhyvUF8/U4MRFAPLXH6FKHa1ouAAQzwP6FcXgUYFR3QdcUlXsXL/q3fef+c/X/HRYgesYtUS3/ncF5b+evvJJQoCbn+wGm1qxZEZUerRg/5bb6AR0jLp3UI5DE4Mb5kzjjsjOslIKFgWkAhHXnpg91V9WobDQfkSGLMTcvBKNOqPRwapBS4P1Zc4ZM2QiApL5HaR3AJIb8u0F4n1CnXpUeLmNDh0k9c5crtCbpMkMNHLMjtgkGWAQSVPslDhCPSGsrEIzIZpM+Q27R5vZnS361OhhB0J5myeR54+res+T+8vlC+AweEtPL6UZ0U5y1nTvcFTlwdH1jhRgyMPQG9Wj6oE4VtgpQnGDF4Jpfzx+KCpA8G+fiMEfWuKSVTL2Q1w0G4AszrTCKs2I1AJ2AhYMlRVPPvU8vStV5DWZP2FvBmt0ucyp0rkF1J1hWGyQ4xvXibrNkxmRLIkpulhez8WKTiYwEXccjgF14SFTD6fgDczt2Y2nucSy+s3hKX1FaWgpdcrSwVhYioVLE/eU+Y1ND8/pUZsLoAFVOfY5JPm6b6kRBW5HRS5HbjnUOLRpgKr8JHbfcuRnRcDhfbGgC4XRiHSlb1WV8bopN/gZdLep5O1uSGN7zqoUCVa0qJ1bywTN+aiS+lUlElB6o31yTcMjgxvSTIaFHI4/gtoM4B7noe5tOQkXQoknGEtFvUnUg52saUQVrnQTBlopuxo7rN7CF0wqbqIj7qIr0quit0B+rbXAbiEJ5Zz9bEMgE/Wxnd69xwtkiDugjXhT4W8RwtTGkF1wIlqKGStEVVxJbdlJpBzFpCK6agsV2wZvmiuXVc8C44Pb53CQRxtDvKiQNKRPEQZOS/fUIWz52z+iAf0044BnaK6QvJRnHLgyYyiL3MC/aLphOJQfw9VfwDQcWqn3ppDmQUwNrylf8fpzIbAQ6LMFP1wVtPzhgmEM65sCRHz6EUx+iMvnfOw9YvgptPW8aA/FE5Vjd1uc0MVfJWfBZdc4sP+pJOhdcBlOVTEdKiInajHa8PetLBhD3pVM3c4fLldK9guM8+DQya8Lp8acOfPesXvNfQW8vv3Ce5hEHThHiEULqli1aaNsY6aWEc9gyJdhW2Gy87Li9kdhMhYpF1DJMFpRgqMSa3BDHmewz7kGSynwIQL6YQ/FIzVya1rBLOgj1tL09sYN0+2imk8TvIOt25JUzdH5jHgHCuFXI2muFpWVjEjDW3p73S7Rc8495KFbD8Fzl8QjNhHd0Rc3oPADkWV3TnXrrrEbtmfEjUrVs36U4iMGW6zmwv1zc/REhF/KJT0diSbRJYHpUwreWc0dPG7oUPZdhma5vFxhlVatkCQb9cCF8BhHOXwAEMSPzyRsrDywD4Ooi7sYxj7qG0UZMkiqO+vom5+t+HVEndpORPUizry3fLaGjuCPp0gGlpjED4ctLaJPDtkWwzEfSH/YvWV7ICZofC2MtPcfmqBmcn6zLRJZDAzbObEYVdO/GEzVDRlN+0NJ7aDiuHYtlHR7ECzVEzihDQUZ1PRkuWiovndhpc9CO63B0F9F3Kbqfk0uBlJsrgZtrY/Pw7cDPLZdh0lAk7WMqm6merJzpopRjJaPwFzyGTx05xihCNOSJvhp237t2mfOLoNDA3mYLvAnwPPDG9V1Q5AiUxYvfgZBWEX3HEn3AxJBOSDVZCrJRx42RnqWNg099Zb5ehHxcxgLsRiZtTayN8+ZrasGmx7Ee484WPN5Py6LAr8Zs3aB6nSwvT0CnjW6USpEJme1l0WsLfMYq05Ywq7ZkxvEzyf0sJscK3tdbkYOGUPTbxcLMpSgMurEOo99Qx4teDhiUIwzgp4TKks8JLWqQ9PX219utkBrkmuXVwTYJiBgKIKGxy/2QDZSXDFhSyZBoTrIOuWy8A2ErROxGwjti0jmmp7CXQEHGPQcVnWOo0CNSN3KBj0J5P1w4DVLgtqMxmKuJKhpxoDUm2vAI6BMyyfogtEi5DLLRcg7q6nu86AaTd+YeyvzJV6b9ksHKPWKaqPRzjgtmttz4ABQbWoXVszVrU9AZ4Gk26AcW4ZYm6ce0lmwRu3DpltI7zHrKeeVuHNxj/C3aUxkHSBGsJeG2RG2dr9pWeqUNrO2CHHibsqqK6pnv5zXZDNTqpgxON0CM5aC3LO63jIUevch7vc/czh3be/9JsPfMZhjmu4jVOODSN3DbJblP3g8N92v7tv3jgC0vUrfQ2DK6ECmQTzHJLVgO0NMnYPLIsC5nzJxJ/jyWk1YoA60oc8FvQbOGdXqy5Ze16w2eFqlDCeHBtTJU5cJcqvqvB+CWpotaQK5GzFQkkUnRvJtZE0lPCnoo6RqLFIBtWjQesMp90rh2q3q8zjmtU9K6ubrDMyjQF1nozRTwlUj0UYh0KJS/3FEYS6fv8URkpDh7ZX1F1rA0as5WVlUxXyBeQZa5bBYlOncsIxf6JeVLe3NFQ9Ekvg+vf/eYTUoeXbnv2PgxHWjEEUF0l/tUWo4aEMei+Ofgbcbg7ihD9ZLzNhtViFmuxh+Ha3C/X/AIYKesm0NAAA");
    decode("ce-dev (commons-collections 3.2.2)", "H4sIAAAAAAAAAM1aWWwcSRkuj+3YcSLWOTYHihMnDnGOyXim546T3fiI49kdO47tHJuwOD095XEnPd2d7hrPOFZWuw+ABA+AFpCQglgJ3tgIiZV44AF2xcNKSAsiEjzwtPACSBwrtIhD4qiqPqa7p3pOZ9mW3O7uqfrrr+//v7/+Ot78E+gtaWDP7exdfp0PSbxcCF3J3YUCGv/yz25+a1A/JQUAqKgAgCO6BqKCUgzpJTm0ygtQD/GqKokCj0RFDi0hHsE5XuYLUMsUVen4sgbhvJKHH67+8EePw5d/vJPIKZ8E5BomrVVMKVimqshQRqFrmesiLC8qCsJl9fvgFRAoJ2iFU+wKa6gohWbx7UoJqSW0DCsI9N5dEfNRq3qSVh9tUH0O6jpWXAf9RfPJqh+j9Uca1J9RtCLYLikFUSaPzsa7wWlFK4Tu5hRdD+mQL4ZKIkvEsnIPyobyKWffuxv2fYGXoXRZU0qqUT3tbL63Fei2keqRiLP5XnCyKfWnxXWzug19GlfvA2caNH9Z49U1UcgUMeqmhFiHHUh4OtAcfmLerG7Dn8LVB8DppprP8jkomQLSbgGN2s/Ilvr9JR1qMl+ETgAGWgaAC3fYA852gXNNCaA9WIKCBnEfVF7Xy4qW77APXKd9sP1whgqINRCwBCUc9SYVRYK8PLUGhXs5pQIGNFiExRzU5jq1SawjVnEJZ/N7W28+1Vn9aLgj9aOcs/n9rTcf67C+Dd/zVP1gg/pTSrHIy/nJEkKKDHbQwG68WHLGqZyzTcEwo/GFIv5i6BILO2WA9mTEnXgcahmPWLLD+ulKidQnV8B+6reftuNcYRfNKEpIxCJ4fW2OV3v7fv3OT/bd+UU3CMyAAUnh8zO8gBQtA7ajNQ3qa4qUr6jPX6QitpX7iUj814UA58FoYeLypeOeb4by9L5ARnANHGaWmLFKTP4g+3bl3TuFAOi9BQ4KirwONZ0mMxk9q8iFxZIsi3IhCz7h+i2PwG6aLY2RbGlsCWm40HgWPKNimauSUp5SSjKCGgJ7HMUy+BPOjHC5nVa5eRzoCWCnsmDQ/oYTJvs7TrtUfFXwn40nzdDMKPXesPbqLx/9688B0HUL9K7zUglW1C5q2CCgdfZUbTChafxGVtRR5bUnQ994l/9mN+jKgB5dfABpetdV7iF3UnkUm3lgdnkuuzI5sZSZQmDnGGVAqEIcAosdrIrNKgIvwVf+sevOo/A//9gNtmVA/xo2t4A7kgV9AsFC2zC7OYAdCMo6RlE3v/ST/pRw5833bbqgiSoy3/rWeU3kZWSi8V984cyQvMURCECZPtFbxQ2Qifbu377xnb+/9vlUgHTVBMjSnpabL5HY/rk3vza046vvf9HKdOMYcNuVexiO3mc/dTtcnjx9qsZ7AwgccGbNEkR6aG5i8cWVzDQeLZPpcD4egSlWqYmFhWzm0jTu2ljNbyJOsUPTcJUvSWjG+Hh8AqfjGzSPnH308+lx+etvGDn3WTAyduPS5NnM/MyYKAsS9sgNpYTGEMRCcNZu2BUb/+pnvn/6RsVJbc/UwHT2x0+u/+4PQ5uXLcAwQw107ZpdWOkT7KBCJwqzmOpQW+IxrV766VsXXn/03lwABLJguyDh9MHBjAEdl8nTOgjsMwglKmNLEDuGJD7gcxIcr1BfP1GDEZRCy3zhOlHsUkXFAYZ4HjCuLgKNBg4YOuKSnmLlgVdvv//2f74SoMX22MWqJb792S8s/fXWk/MUBNz+cDXa1IojM6L044cDN19Ho6Rl0rv5MgcOj2xaM47bowbJSChYFpEER19+6PRVY1qGw0H5PDjnJOTwxVgsmIgOUwtcOFZf4jF7hkRUWCK3s+QWQkZblr1IrFepS48RN6fBoZu8zpLbRXKbJIGJXrbZAYMsgwwq+ZKFCkegL5KLR2GOo82Q27R3vJkx3K5fgzJ2JJh3eB55esHQfY7er5bPgOGRTTy+lC9LSo63p3vDRy8Mj67ykg5HH4K+nBFVCcI3wfUmGDN8MZIOJhLDlg4E+/qNEPTtKSZRLe80wF6nAazqTCOsOIxAJWAjYMlQ0/DsUy/Qtz5RXlWMF/Jmtkqfy7wmk19I1esMk+1jfPMzWbdpMjOSpTBN9zv7sUjBwQQu4pa55VR6MZuYflG9Jl+D6xOl9Au5vKrN318UCg/uxe9fvXpJTCxzcro8mbxZrEQnFORwASygOscmn3Rf9yUlqsj1UOR6cM+hLKANFVbhI7f7tiO7LwYK7Y0BXR6MIqQrz9hdOUcn/SYvU84+HanNDWl8N0CFGtGSFq17Y5m4MRc9SqdjTApSb6xPvhFwYGRTVtCwmMfxX0QbIdzzAsxnZDfp0iDpDmvxWDCZdrGLLYWwyoNm2kQz7URzl9ND6IJJ1UUC1EUCVXJVnA7Qv7UOwCd9sZytj2UIfLI2vtO772iRAgkPrMlgOuI/WljSCKqDblQjEXuNqIoruS0zgZy1gVQtR2W5YsvwxfLtuuJJMDSyeRQHcbQxLEgiSUcKEGWVgnJNE0+ecvgjHtCPuwZ0iup1ko/ilANPZlRjmRMYF00nVJf6O6n6g4COU9uM1lzKzINzI5vGd5zOrIsCJMpM0Q8ndSNvmEA448qVEDGPURSjP/ryKR9bvwRuuG2dCAcjXLpq7HabO1bBV/k5cN4jngum3AytAy7LoaKWQ0WdRB2qDXvT4roz6FXN3OHw5XWtcLvMPA32WfB6fGrQmz8bFb/b0FvI798juHMg7ME9Sihc0qSqTRtjHbOwjvkGRboK2wyX3ZcfszsIkfFou4ZIgeOMFBiTWodZ8jyLfcg3WE6BCQ/SyWAkHK+TW9cIZkGfsJemtzBuHmkV00SC5B1e3VKWbq7MY9A9Vor5Gk1xtZyiYUaa2tLf6XaLkXE+QxaygxS44Jpoxj66I+LxHgR6VE3x5lzb6xK7ZX9K1qxYNetPETJmeM1uLdQ3P0dLRoORSMrfkRwSWR6Utqzkn9HQxe+GDuXYZWiax0MMq7RsgbDQrgXOgP04yuEBhiR+eCJlY+WDfQLEPNjHMfYxxyjIkkVQ311F3fruwKsl7tJyFqhnDeS7ldVVdgR9OkE0ssogPBe2t4l8O+RYDMR9If/i9ZXsgJkRbkuZaW0/tcDMVH1mOiQymMlZOTHnyYk/bIaKluymveHwVlCRi28ZFa0ONEvFFE5IIwk2FW1ZHipa3x14OYPgbmcQNHYht5iaT4Ob0RSLm5y9/flx4GZYyLXrKFFwpJZJ1c1UX3bWTDFSsfoJmEsmi5/WFIOLuiFthp+O7d+mfeLgFjA0nIftAn8KPDuyWVU7BGUyYfXjZwxwHrgTbrgZkgjIe6sgV0u48HIy1LWwae2tt8rRj4qZ4XyExcyYvZG/dcxsWTXY9iLcacLHmsn5giKJwkbN2gep0sL09CJ4zu1E6QiZntZdFnC2zGKtNWPiPDOmtwieT2lhNrza9rpcHBx1hiZBKRYVOcQXNAiNnvoGvFrw8EQhnGAFPKZUFngp+9SHr6+2Pt3sANcU3y6uSTDCQEDVxHVe2GiA7CS46EGWTAO4Osh65TKwjYbtEzFbiG3LiKbbXgIdBYcYdFxW9E6jQM3IHQmHg6lU/TBgt8uC2kqGop5k6KnGgHTbK4DnwAmWT9EFokXI55fXIO6ur7vOgGkvfhz2V+ZKvb9sFo4x+xTVxyMc8Fu1tmfCgKBW1K+smqvavgBPg0kvwDi3jDA3zv0ks+BN2IfMthDeQ/ZTb6vw5hIf4e7SOZDygBrBXhtmRtna/aVnq1A6ztgh14m7KqieqZ7xc12QrU5qYNTndAjOWteUvN/xkIP2uQ9vufvZ/Ttufek3HwTMwxxXcBtHXRtG3hpktyj3wf6/7Xhn15x5BKTrV8YaBl9Ca2QSLPBI0UKON8jYPbAtCpjzJQt/XiCn1YgB6kg/5rOg38A5u1p1ydrzgs0OV2OE8eTYmCbz0gpRfkWD90tQRyslTSRnK+ZLkuTeSK6NpJFkMB1zjUSNRTKoHgvbZzidXnmsdrvKOq5Z3bOyu8k6I9MYUPfJGOOUQPVYhHkolLjUX1xBqOv3T2GkNHVoe0XdszZgxlpBUTc0sbCGfGPNMlhs6lQOFw8m60V1Z0vHqkdiCVz//j+PkAa0Qtuz/3EwypoxSNIi6a++CHU8lEH/xdFPg1vNQZwMpuplJqwWq1CTPYzAjnah/h/Wo9rptDQAAA==");
    decode("ce-dev (commons-collections 3.2.2) + com.sun.faces.ClientStateSavingPassword", "");
}

}

@yurem
Copy link
Contributor Author

yurem commented Dec 1, 2015

It's not convinient to update web.xml in every VM to secure it...
Maybe it's possible to change WebConfiguration before JSF will get value from it... In this case we can generate password on the fly at startup.

@yuriyz
Copy link
Contributor

yuriyz commented Dec 1, 2015

Isn't it easier to upgrade jsf, which already generates passwords on the fly.? Then we will also benefits from all other new stuff there.

@nynymike
Copy link
Contributor

nynymike commented Dec 1, 2015

Actually, we can generate web.xml during installation. So it doesn't seem like such a big deal to render a random password.

@yurem
Copy link
Contributor Author

yurem commented Dec 1, 2015

In setup.py we have method which update oxCas.war during install. We can use this method as reference for oxath.war update: https://github.com/GluuFederation/community-edition-setup/blob/master/setup.py#L999

@nynymike
Copy link
Contributor

nynymike commented Dec 1, 2015

ok, I changed my mind. Having to recreate the war is messy and would make upgrades harder.

@yurem
Copy link
Contributor Author

yurem commented Dec 10, 2015

I have tried to find solution for this today. 100% pure programmatic way is not possible because JNDI was developed for services integration. Also when I try to change JNDI context properties it throw exception that Context is read only.

I find another solution. It's not bed too: GluuFederation/community-edition-setup@9d2f97d

Setup put file $TOMCAT_HOME/conf/Catalina/localhost/oxauth.xml during install. This value override default value in oxauth.war/WEB-INF/web.xml:

< Context >
< Environment name="com.sun.faces.ClientStateSavingPassword" value="%(oxauth_jsf_salt)s" type="java.lang.String" override="false" />
< /Context >

@yurem yurem closed this as completed Dec 10, 2015
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants