...
To quickly get started using permissions for JMX and GFSH a sample implementation of comof org.gemstoneapache.gemfiregeode.security.Authenticator and com.gemstone.gemfire.security.AccessControl
is SecurityManager is provided by the class comorg.gemstoneapache.gemfiregeode.security.templates.SampleJsonAuthorizationSampleSecurityManager
. This implementation requires a JSON file which defines the allowed users and their corresponding permissions. For example:
...
Copy the above "security.json" file into locator's directory (locator1 in the example below) or make it available on the classpath using the --classpath option while starting the locator.
Using gfsh, start a locator with security activated.
Code Block language bash gfsh> start locator --name=locator1 \ --J=-Dgemfire.security-client-authenticatormanager=comorg.gemstoneapache.gemfiregeode.security.templates.SampleJsonAuthorization.create \ --J=-Dgemfire.security-client-accessor=com.gemstone.gemfire.security.templates.SampleJsonAuthorization.createSampleSecurityManager
Similarly, start a server
Code Block gfsh> start server --name=server1 --locators=localhost[10334]
Start a new instance of gfsh and connect with one of the users defined in your JSON file. The super-user should be allowed to do everything in gfsh.
Code Block gfsh> connect --locators=localhost[10334] --user=super-user --password=1234567
Disconnect and reconnect with a user with lesser privileges:
Code Block gfsh> disconnect gfsh> connect --locators=localhost[10334] --user=joebloggs --password=1234567 gfsh> stop server --name=server1 An error occurred while attempting to stop a Cache Server: Subject does not have permission [CLUSTER:READ]
- Currently, changes to the security.json file require the locator to be restarted.
...