Win a copy of Five Lines of Code this week in the OO, Patterns, UML and Refactoring forum!
  • Post Reply Bookmark Topic Watch Topic
  • New Topic
programming forums Java Mobile Certification Databases Caching Books Engineering Micro Controllers OS Languages Paradigms IDEs Build Tools Frameworks Application Servers Open Source This Site Careers Other all forums
this forum made possible by our volunteer staff, including ...
  • Campbell Ritchie
  • Bear Bibeault
  • Ron McLeod
  • Jeanne Boyarsky
  • Paul Clapham
  • Tim Cooke
  • Liutauras Vilda
  • Junilu Lacar
Saloon Keepers:
  • Tim Moores
  • Stephan van Hulst
  • Tim Holloway
  • fred rosenberger
  • salvin francis
  • Piet Souris
  • Frits Walraven
  • Carey Brown

Spring LDAP/Active Directory Security: Authenticate User w/out Using an Admin/Mgr Account

Posts: 2
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
I am using Spring Security 3.1.0M2 and LDAP 1.3.1, the most current as of this date, to authenticate users via a login form. I am trying to determine if it is possible to eliminate the need for an admin/mgr account, as declared below in the DefaultSpringSecurityContextSource. On our LDAP server, all users are able to connect to and query the server, so there is no need for an admin account to do this and this is actually undesirable for our company needs. Can anyone state that this is definitely not possible with Spring Security, or if it is possible point me to either configuration or code to accomplish this?

I am successfully authenticating users with the following Spring configuration:
-=> Gregg <=-
Posts: 17346
Mac IntelliJ IDE Spring
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
It might be possible with Spring's Expression Language. Spring Security supports the expression language.

Or you can always customize Spring Security to do this. In this case, those Spring LDAP classes can be extended or I am sure there is an interface that you can implement and then you write custom code in the setUserDn or setPassword methods, but it might also entail overriding methods in the other LDAP classes that reference the "ldapServer" bean and then take the data coming in through the Http request from the login form.

Or, doing a Google search or two I found this!/org/springframework/ldap/core/AuthenticationSource.html

You might just implement this method and that would be the only custom class you need to deal with in Java, then add it to the config and use your custom one.


Posts: 1
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
Hi Gregg,

I am new to Spring Security and your post looks quite useful. I have a similar requirement of integrating with Active Directory.

In your security application context can you please throw some light on the functionality of the class "".

Also if you can put some light on your web layer, i mean your web.xml and any jsp's for controlling the authorization it would be very helpful.

Listen. That's my theme music. That's how I know I'm a super hero. That, and this tiny ad told me:
Building a Better World in your Backyard by Paul Wheaton and Shawn Klassen-Koop
    Bookmark Topic Watch Topic
  • New Topic