锘??xml version="1.0" encoding="utf-8" standalone="yes"?>亚洲无圣光一区二区,亚洲6080yy久久无码产自国产 ,亚洲区小说区激情区图片区http://www.tkk7.com/algz/category/47753.htmlPurple Butterfly Flying QQ緹?7101519 Flex,Ext,Spring,Hibernate,EOS,SpringSecurity,Strutszh-cnThu, 03 Mar 2011 11:09:44 GMTThu, 03 Mar 2011 11:09:44 GMT60X.509 瀛︿範絎旇璇﹁Вhttp://www.tkk7.com/algz/articles/345601.html绱澏鈭忛鎻氣啑绱澏鈭忛鎻氣啑Thu, 03 Mar 2011 08:19:00 GMThttp://www.tkk7.com/algz/articles/345601.htmlhttp://www.tkk7.com/algz/comments/345601.htmlhttp://www.tkk7.com/algz/articles/345601.html#Feedback0http://www.tkk7.com/algz/comments/commentRss/345601.htmlhttp://www.tkk7.com/algz/services/trackbacks/345601.htmlX.509瀹岀粨

鍙傝冩枃妗?  緇堟瀬姝﹀櫒鈥旀暟瀛楄瘉涔?http://book.51cto.com/art/201004/192437.htm

         鐢⊿SL榪涜鍙屽悜韜喚楠岃瘉鎰忔濆氨鏄湪瀹㈡埛鏈鴻繛鎺ユ湇鍔″櫒鏃訛紝閾炬帴鍙屾柟閮借瀵瑰郊姝ょ殑鏁板瓧璇佷功榪涜楠岃瘉錛屼繚璇佽繖
鏄粡榪囨巿鏉冪殑鎵嶈兘澶熻繛鎺ワ紙鎴戜滑閾炬帴涓鑸殑SSL鏃墮噰鐢ㄧ殑鏄崟鍚戦獙璇侊紝瀹㈡埛鏈哄彧楠岃瘉鏈嶅姟鍣ㄧ殑璇佷功錛屾湇鍔″櫒涓嶉獙璇佸鎴?br /> 鏈虹殑璇佷功銆傝岃繛鎺ョ綉涓婇摱琛屾椂浣跨敤鐨刄鐩懼氨鏄敤鏉ュ瓨鍌ㄨ繘琛屽弻鍚戦獙璇佹墍闇瑕佺殑瀹㈡埛绔瘉涔︾殑錛夈?/p>

娉? 璇佷功鏇存敼鎿嶄綔(瀵煎叆,鍒犻櫎絳?,閮藉繀闇閲嶅惎WEB搴旂敤.鍚﹀垯璇佷功搴撶殑緙撳瓨鏃犳硶娓呴櫎.涓鑸鎴風鐨勮瘉涔︿笉闇鍚婇攢,涔熸病鎰忎箟,鐩存帴璁╁叾鏃犳硶鐧婚檰灝辮.
spring security3 鐨刋.509閰嶇疆鍦ㄥ弻鍚戣璇佷腑,鍙洿鎺ョ櫥褰?鍗崇綉閾朵腑浣跨敤U鐩懼氨鍙互涓嶇敤杈撳叆鐢ㄦ埛鍚嶅拰瀵嗙爜鐩存帴鐧誨綍緋葷粺.
<http>
    <intercept-url pattern="/admin.jsp" access="ROLE_ADMIN" requires-channel="https"/>
    <intercept-url pattern="/**" access="ROLE_USER"  requires-channel="https"/>
    <x509 subject-principal-regex="CN=(.*?)," user-service-ref="userService"/>
</http>

<user-service id="userService">
    <user name="admin" password="admin" authorities="ROLE_USER, ROLE_ADMIN" />
    <user name="user" password="user" authorities="ROLE_USER" />
</user-service>

 

鑾峰緱瀹夊叏璇佷功鏈変袱縐嶆柟寮忥細
(1)涓縐嶆柟寮忔槸鍒版潈濞佹満鏋凜A璐拱
瑕佽幏寰楁暟瀛楄瘉涔︼紝鎴戜滑闇瑕佷嬌鐢ㄦ暟瀛楄瘉涔︾鐞嗗伐鍏鳳紙濡侹eyTool鍜孫penSSL錛夋瀯寤篊SR錛圕ertificate Signing Request錛屾暟瀛楄瘉涔︾鍙戠敵璇鳳級錛屼氦鐢盋A鏈烘瀯絳懼彂錛?/p>

褰㈡垚鏈緇堢殑鏁板瓧璇佷功銆?br /> (2)榪樻湁涓縐嶆柟寮忔槸鍒涘緩鑷垜絳懼悕鐨勮瘉涔?/p>

keystore:keystore鎵╁睍鍚嶇殑鏂囦歡(鍗矹KS綾誨瀷)涓竴鑸繚瀛樼殑鏄垜浠殑縐侀挜錛岀敤鏉ュ姞瑙e瘑鎴栬呬負鍒漢鍋氱鍚?br /> truestore:淇濆瓨鐨勬槸涓浜涘彲淇′換鐨勮瘉涔︼紝涓昏鏄闂煇涓猦ttps鐨勬椂鍊欏璁塊棶鑰呰繘琛岃璇侊紝浠ョ‘淇濆叾鍙俊浠匯?br /> truststore:鍙屽悜璁よ瘉涓槸蹇呴』鐨勶紝濡傛灉娌℃湁鏄懼紡鐨勬寚瀹氾紝榛樿鎸囧畾涓?JAVA_HOME/lib/security/cacerts 榪欎釜鏂囦歡銆?br /> 鍙屽悜SSL璁よ瘉錛屾湇鍔″櫒蹇呴』瑕佷俊浠誨鎴風璇佷功錛屽洜姝わ紝蹇呴』鎶婂鎴風璇佷功娣誨姞涓烘湇鍔″櫒鐨勪俊浠昏璇佷腑蹇?鍗?JAVA_HOME/lib/security/cacerts 榪欎釜鏂囦歡
1錛塊eyStore: 鍏朵腑淇濆瓨鏈嶅姟绔殑縐侀挜
2錛塗rust KeyStore:鍏朵腑淇濆瓨瀹㈡埛绔殑鎺堟潈璇佷功

 

涓.Keytool鏄竴涓狫ava鏁版嵁璇佷功鐨勭鐞嗗伐鍏楓?
1.keystore 鏂囦歡
Keytool鏄竴涓瘉涔﹀簱鏂囦歡,鍙皢N涓瘑閽ワ紙key錛夊拰璇佷功錛坈ertificates錛夊瓨鍦ㄤ竴涓О涓簁eystore鐨勬枃浠朵腑,涔熷嵆N涓潯鐩殑鎰忔?
 鍦╧eystore閲岋紝鍖呭惈涓ょ瀵瑰簲鐨勬暟鎹細
(1)瀵嗛挜瀹炰綋錛圞ey entity錛? 瀵嗛挜錛坰ecret key錛夊張鎴栬呮槸縐侀挜鍜岄厤瀵瑰叕閽ワ紙閲囩敤闈炲縐板姞瀵嗭級
(2)鍙俊浠葷殑璇佷功瀹炰綋錛坱rusted certificate entries錛? 涔熷彲縐頒負鍏挜.

2.鍙傛暟璇存槑
鍙傛暟璇存槑錛?
-genkey  鍒涘緩璇佷功搴?
-import      灝嗗凡絳懼悕鏁板瓧璇佷功瀵煎叆瀵嗛挜搴?nbsp; keytool -import -alias sage -keystore sagely -file sagely.crt
             瀵煎叆宸茬鍚嶆暟瀛楄瘉涔︾敤keytool -list -v 浠ュ悗鍙互鏄庢樉鍙戠幇澶氫簡璁よ瘉閾鵑暱搴︼紝騫朵笖鎶婃暣涓狢A閾懼叏閮ㄦ墦鍗板嚭鏉ャ?br /> -delete 鍒犻櫎鎸囧畾鍒悕鐨勬潯鐩?瀵嗛挜鍙婅瘉涔?
-trustcacerts 琛ㄧず灝嗘暟瀛楄瘉涔﹀鍏ヤ俊浠誨簱銆?br /> -alias 瀵嗛挜鍒悕(浠繪剰涓嶉噸澶?.璇佷功瀹炰綋鍏寵仈鐫瀵嗛挜瀹炰綋,鍙氳繃鍒悕鍒犻櫎鏁翠釜鏉$洰(璇佷功).
-dname 琛ㄧず瀵嗛挜鐨凞istinguished Names錛?
        CN=commonName  鍗沖浜庢湇绔瘉涔︽椂涓虹綉绔欏煙鍚?瀹㈡埛绔垯浠繪剰.閫氬父浣跨敤鍩熷悕鎴栧甫鏈夐氶厤絎?#8220;*”鐨勬硾鍩熷悕錛屽“*.zlex.org”鏍囪瘑鐢ㄦ埛韜喚銆?br />         OU=organizationUnit
        O=organizationName
        L=localityName
        S=stateName
        C=country
Distinguished Names琛ㄦ槑浜嗗瘑閽ョ殑鍙戣鑰呰韓浠?
-keyalg   鎸囧畾瀵嗛挜鐨勫姞瀵嗙畻娉曪紝鏀寔RSA(閫氬父)鍜孌SA鍏?縐嶇畻娉曪紝榛樿綆楁硶涓篋SA銆?br /> -keypass 瀵嗛挜鐨勫瘑鐮?/p>

-keystore 鎸囧畾keystore鏂囦歡鍙婅礬寰?浜х敓鐨勪俊鎭瓨鍦?keystore鏂囦歡涓?
濡傛灉涓嶈緗?鍒欓粯璁ゅ湪鎿嶄綔緋葷粺鐨勫綋鍓嶇敤鎴?濡侫LGZ)鐩綍涓嬬敓鎴愬悕涓?#8220;.keystore”鐨勬枃浠?榪樹細浜х敓涓涓猰ykey鐨勫瘑閽ュ埆鍚?mykey涓寘鍚敤鎴風殑鍏挜銆佺閽ュ拰璇佷功銆?br /> 鍦╓nidows涓嬶紝鏂囦歡鐨勪綅緗負錛欳:\Documents and Settings\ALGZ\.keystore
鍦↙inux涓嬶紝璇ユ枃浠剁殑浣嶇疆涓猴細home\ALGZ\.keystore

-storepass 璁塊棶keystore(瀵嗛挜搴?鐨勫瘑鐮侊紝榪欎釜瀵嗙爜鎻愪緵緋葷粺浠巑ykeystore鏂囦歡涓皢淇℃伅鍙栧嚭
-validity 璇ュ瘑閽ョ殑鏈夋晥鏈?浠ュぉ涓哄崟浣?/p>

-keysize     鎸囧畾瀵嗛挜闀垮害,浠ヤ綅涓哄崟浣?
-file        鍙傛暟鎸囧畾瀵煎嚭璇佷功鐨勬枃浠跺悕.
-sigalg 鎸囧畾鏁板瓧絳懼悕綆楁硶錛岃繖閲屾寚瀹氫負SHA1withRSA綆楁硶,閫氬父涓嶇敤璁劇疆銆?br /> -rfc 鎸囧畾浠ase64緙栫爜鏍煎紡杈撳嚭,閫氬父涓嶈緗?/p>


3.浣跨敤姝ラ:
(1)鐢熸垚璇佷功搴?br /> 鐢熸垚瀵嗛挜錛屽茍浠ヨ瘉涔﹀簱鏂囦歡鏂瑰紡淇濆瓨
 keytool -genkey -alias bogus -keysize 512 -validity 3650 -keyalg RSA -dname "CN=bogus.com, OU=XXX CA, O=Bogus Inc, L=Stockholm, S=Stockholm,

C=SE" -keypass boguspw -storepass boguspw -keystore sean.cert

2.瀵煎嚭璇佷功
浠庤瘉涔﹀簱涓?-keystore)灝嗘寚瀹氬埆鍚嶇殑璇佷功瀵煎嚭涓鴻瘉涔︽枃浠?-file)
渚嬪錛歬eytool -export -keystore monitor.keystore -alias monitor -file monitor.cer
灝嗘妸璇佷功搴?monitor.keystore 涓殑鍒悕涓?monitor 鐨勮瘉涔﹀鍑哄埌 monitor.cer 璇佷功鏂囦歡涓?瀹冨寘鍚瘉涔︿富浣撶殑淇℃伅鍙婅瘉涔︾殑鍏挜錛屼笉鍖呮嫭縐侀挜錛屽彲浠ュ叕寮銆?br /> keytool -export -keystore d2aApplet.keystore -alias RapaServer -file Rapa.cert -storetype IAIKKeystore

3.瀵煎叆璇佷功
灝嗘寚瀹氬埆鍚嶇殑璇佷功(-file)涓鍏ュ埌keystore璇佷功搴?-keystore)涓?br /> 榪欓噷鍚慗ava榛樿鐨勮瘉涔?cacerts瀵煎叆Rapa.cert
keytool -import -alias RapaServer -keystore cacerts -file Rapa.cert
閫氬父璇ュ懡浠ょ敤浠ュ鍏ユ潵鑷狢A涓績鐨勮瘉涔︼紙Importing a Certificate for the CA錛?

4.鍒犻櫎璇佷功搴撲腑鐨勬潯鐩?鍗沖瘑閽ュ疄浣撲笌璇佷功瀹炰綋)
keytool -delete -alias RapaServer -keystore d2aApplet.keystore 錛岃繖鏉″懡浠ゅ皢 d2aApplet.keystore 涓殑 RapaServer 榪欎竴鏉¤瘉涔﹀垹闄や簡銆?/p>

5.璇佷功鏉$洰鍙d護鐨勪慨鏀?br /> 浣跨敤 -keypasswd 鍙傛暟錛屽錛歬eytool -keypasswd -alias RapaServer -keystore d2aApplet.keystore錛屽彲浠ヤ互浜や簰鐨勬柟寮忎慨鏀?d2aApplet.keystore璇佷功搴撲腑鐨勬潯鐩?/p>

涓?RapaServer 鐨勮瘉涔︺?br /> Keytool -keypasswd -alias RapaServer -keypass 654321 -new 123456 -storepass 888888 -keystore d2aApplet.keystore榪欎竴琛屽懡浠や互闈炰氦浜掑紡鐨勬柟寮忎慨鏀瑰簱

涓埆鍚嶄負 RapaServer 鐨勮瘉涔︾殑瀵嗙爜涓烘柊瀵嗙爜 654321錛岃涓殑 123456 鏄寚璇ユ潯璇佷功鐨勫師瀵嗙爜錛?888888 鏄寚璇佷功搴撶殑瀵嗙爜銆?/p>

6. 瀵煎嚭璇佷功鍒版柊鐨凾rustStore(淇′換鐨勮瘉涔﹀簱)
 keytool -import -alias 鍒悕 -file 鏂囦歡鍚?-keystore truststore

7.    鏌ョ湅Keystore鏂囦歡鍐呭
榪涘叆JDK瀹夎鐩綍涓嬬殑bin鐩綍錛岃繍琛宬eytool鍛戒護銆?
keytool -list -keystore C:\keystore.jks -storepass password

 -v              鏄劇ず瀵嗛挜搴撲腑鐨勮瘉涔﹁緇嗕俊鎭?/p>

***********************************************

cacerts璇佷功鏂囦歡(The cacerts Certificates File)
璇佷功鏂囦歡瀛樺湪浜巎ava.home\lib\security鐩綍涓嬶紝鏄疛ava緋葷粺鐨凜A璇佷功浠撳簱

CA璇佷功鐨勫鍏ワ紙Importing Certificates錛?
鍛戒護錛?br /> 寮曠敤
keytool -import -alias joe -file jcertfile.cer

榪欎釜鍛戒護灝嗚瘉涔︽枃浠秊certfile.cer涓埆鍚嶄負joe鐨勮瘉涔﹀鍏ョ郴緇熺殑鍙椾俊浠昏瘉涔﹀垪琛ㄤ腑
閫氬父璇ュ懡浠ょ敤浠ュ鍏ユ潵鑷狢A涓績鐨勮瘉涔︼紙Importing a Certificate for the CA錛?

瀵煎叆琚獵A涓績鎺堟潈鐨勮瘉涔︼紙Importing the Certificate Reply from the CA錛?
鍛戒護錛?br /> 寮曠敤
keytool -import -trustcacerts -file VSMarkJ.cer

 

璇佷功鐨勫鍑猴紙Exporting Certificates錛?
鍛戒護錛?br /> 寮曠敤
keytool -export -alias jane -file janecertfile.cer

榪欎釜鍛戒護灝嗗埆鍚嶄負jane鐨勮瘉涔﹀鍑哄埌璇佷功鏂囦歡jcertfile.cer涓?
鐢熸垚鐨勮瘉涔﹀彲浠ヤ氦浠樺鎴風鐢ㄦ埛浣跨敤錛岀敤浠ヨ繘琛孲SL閫氳錛屾垨鑰呬即闅忕數瀛愮鍚嶇殑jar鍖呰繘琛屽彂甯冭呯殑韜喚璁よ瘉銆?/p>


*************************************


緗戜笂鏈夎澶氭暀紼嬶紝浣嗘病鏈夎鏄?43涓?443,http涓巋ttps鐨勫尯鍒紝璁╀漢璇曟潵璇曞幓鎬繪湁涓嶇埥鐨勫湴鏂廣傛病鏈夎鏄庢庢牱嫻嬭瘯錛屽懙鍛碉紝鎴戣鏄庝竴涓嬶細


Tomcat6閰嶇疆HTTPS

鎴戜嬌鐢ㄧ殑JDK鐗堟湰涓篔DK6錛屼嬌鐢ㄧ殑鐨凾omcat鐗堟湰涓?錛涢厤緗甌omcat涓嬬殑HTTPS鍏跺疄寰堢畝鍗曪紝鍙渶瑕佸畬鎴愪袱姝ュ伐浣滃氨鍙互 浜嗭紱SSL璁よ瘉鍒嗗弻鍚戣璇佸拰鍗曞悜璁よ瘉錛屽

鏋滀負鍙屽悜璁よ瘉鍒欏鎴風涔熼渶瑕佸畨瑁呭凡鐢熸垚濂界殑鏂囦歡銆?/p>


鎴戞妸鐢熸垚鐨?#8220;鏈嶅姟鍣ㄨ瘉涔︽枃浠?#8221;鍙栧悕涓簊erver.jks銆傜畝鍗曡搗瑙侊紝鎴戞妸server.jks鏀懼湪D鐩樻牴鐩綍涓嬮潰,閰嶇疆鐜涓簑indows.
棣栧厛浣跨敤JDK鑷甫鐨勫伐鍏穔eytool鐢熸垚涓涓?#8220;鏈嶅姟鍣ㄨ瘉涔?#8221;錛屽彇鍚嶄負server.jks銆?/p>

涓.tomcat6閰嶇疆鍙屽悜璁よ瘉

1銆佺敓鎴愭湇鍔″櫒绔瘉涔?br /> x:\>keytool -genkey -keyalg RSA -dname "cn=localhost,ou=sango,o=none,l=china,st=beijing,c=cn"
-alias server -keypass password -keystore d:\server.jks -storepass password -validity 3650
鏈嶅姟绔殑CN鍊煎繀欏諱負鍩熷悕,涓嶇劧瀹㈡埛绔璇佹椂涓洪潪娉?

2銆佺敓鎴愬鎴風璇佷功
X:\>keytool -genkey -keyalg RSA -dname “cn=sango,ou=sango,o=none,l=china,st=beijing,c=cn”
-alias custom -storetype PKCS12 -keypass password -keystore d:\custom.p12
-storepass password -validity 3650  
瀹㈡埛绔殑CN鍙互鏄換鎰忓箋?/p>

3銆佺敱浜庢槸鍙屽悜SSL璁よ瘉錛屾湇鍔″櫒蹇呴』瑕佷俊浠誨鎴風璇佷功錛屽洜姝わ紝蹇呴』鎶婂鎴風璇佷功娣誨姞涓烘湇鍔″櫒鐨勪俊浠昏璇併傜敱浜庝笉鑳界洿鎺ュ皢PKCS12鏍煎紡鐨勮瘉涔﹀簱瀵煎叆錛屾垜浠?/p>

(1)蹇呴』鍏堟妸瀹㈡埛绔瘉涔﹀鍑轟負涓涓崟鐙殑CER鏂囦歡錛屼嬌鐢ㄥ涓嬪懡浠わ紝鍏堟妸瀹㈡埛绔瘉涔﹀鍑轟負涓涓崟鐙殑cer鏂囦歡錛?br /> X:\>keytool -export -alias custom -file d:\custom.cer -keystore  d:\custom.p12 -storepass password -storetype PKCS12 -rfc  
(2)鐒跺悗錛屾坊鍔犲鎴風璇佷功鍒版湇鍔″櫒涓紙灝嗗凡絳懼悕鏁板瓧璇佷功瀵煎叆瀵嗛挜搴擄級
X:\>keytool -import -v -alias custom -file d:\custom.cer -keystore  d:\server.jks -storepass password  

4銆佹煡鐪嬭瘉涔﹁緇?-v)鍐呭
keytool -list -v -keystore d:\server.jks -storepass password  

5銆侀厤緗畉omcat service.xml鏂囦歡
<Connector port=“8443″ protocol=“HTTP/1.1″ SSLEnabled=“true”  maxThreads=“150″ scheme=“https” secure=“true” 
clientAuth=“true” sslProtocol=“TLS” 
keystoreFile="D:/server.jks" keystorePass="password"
truststoreFile="D:/server.jks" truststorePass="password"  /> 

涓嶈緗畉ruststoreFile,truststorePass灞炴?鍗抽粯璁ゆ寚鍚?%JAVA_HOME%/JRE/LIB/SECURITY/CACERTS"鏂囦歡(JKS綾誨瀷),鍒欏湪鍙屽悜璁よ瘉涓?闇鎶婂鎴風璁よ瘉瀵煎叆鍒版

鏂囦歡涓?
clientAuth=”true”琛ㄧず鍙屽悜璁よ瘉

6銆佸鍏ュ鎴風璇佷功鍒版祻瑙堝櫒
鍙屽悜璁よ瘉闇瑕佸己鍒墮獙璇佸鎴風璇佷功銆傚弻鍑?#8220;custom.p12”鍗沖彲灝嗚瘉涔﹀鍏ヨ嚦IE

浜?tomcat6閰嶇疆鍗曞悜璁よ瘉

1銆佺敓鎴愭湇鍔″櫒绔瘉涔?br /> X:\>keytool -genkey -keyalg RSA -dname “cn=localhost,ou=sango,o=none,l=china,st=beijing,c=cn”
-alias server -keypass password -keystore d:\server.jks -storepass password -validity 3650  

2銆佺敱浜庢槸鍗曞悜璁よ瘉錛屾病鏈夊繀瑕佺敓鎴愬鎴風鐨勮瘉涔︼紝鐩存帴榪涘叆閰嶇疆tomcat service.xml鏂囦歡,Xml浠g爜
<Connector port=”8443″ protocol=”HTTP/1.1″ SSLEnabled=”true”
maxThreads=”150″ scheme=”https” secure=”true”
clientAuth=”false” sslProtocol=”TLS”
keystoreFile=”D:/server.jks” keystorePass=”password”/>

clientAuth=”false”琛ㄧず鍗曞悜璁よ瘉錛屽悓鏃跺幓鎺夋湇鍔$鐨勫彲淇′換璁よ瘉,鍗?truststoreFile=”D:/server.jks” truststorePass=”password”榪?涓睘鎬?.

嫻嬭瘯璇存槑錛?/p>

1.璇鋒敞鎰忔湰鏈烘祴璇曠殑緗戝潃鏄細https://localhost:8443

2.濡傛灉灝唗omcat鐨?server.xml 鐨?443 鏇存敼涓?443,娉ㄦ剰鏈満鐨?43鏄惁寮鍚?/p>

3.濡傛灉浣犵殑tomcat 浣跨敤浜唄ttp://localhost:8080,嫻嬭瘯緗戝潃涔熸槸https://localhost:8443

鍏跺畠錛氬綋浣跨敤https璁塊棶鏌愪竴鍩熷悕鏃訛紝嫻忚鍣ㄩ粯璁よ闂湇鍔″櫒鐨?43绔彛銆傚唴閮ㄥ鐞嗗悗錛屽啀杞悜80澶勭悊銆傛墍浠sl 鍏ㄧОSecurity Socket Layer, 鍔犲瘑濂楁帴瀛楀崗璁眰 鍚?/p>

瀛楁病鏈夋敼閿欙紝鍙槸涓涓姞瀵嗗眰



绱澏鈭忛鎻氣啑 2011-03-03 16:19 鍙戣〃璇勮
]]>
RBAC鍩轟簬瑙掕壊鐨勮闂帶鍒訛紙Role-Based Access Control錛?/title><link>http://www.tkk7.com/algz/articles/344009.html</link><dc:creator>绱澏鈭忛鎻氣啑</dc:creator><author>绱澏鈭忛鎻氣啑</author><pubDate>Thu, 10 Feb 2011 02:29:00 GMT</pubDate><guid>http://www.tkk7.com/algz/articles/344009.html</guid><wfw:comment>http://www.tkk7.com/algz/comments/344009.html</wfw:comment><comments>http://www.tkk7.com/algz/articles/344009.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.tkk7.com/algz/comments/commentRss/344009.html</wfw:commentRss><trackback:ping>http://www.tkk7.com/algz/services/trackbacks/344009.html</trackback:ping><description><![CDATA[<p>        鍩轟簬瑙掕壊鐨勮闂帶鍒訛紙Role-Based Access Control錛変綔涓轟紶緇熻闂帶鍒訛紙鑷富璁塊棶錛屽己鍒惰闂級鐨勬湁鍓嶆櫙鐨勪唬鏇垮彈鍒板箍娉涚殑鍏蟲敞銆傚湪RBAC涓紝鏉冮檺涓庤鑹茬浉鍏寵仈錛岀敤鎴烽氳繃鎴愪負閫傚綋瑙掕壊鐨勬垚鍛樿屽緱鍒拌繖浜涜鑹茬殑鏉冮檺銆傝繖灝辨瀬澶у湴綆鍖栦簡鏉冮檺鐨勭鐞嗐傚湪涓涓粍緇囦腑錛岃鑹叉槸涓轟簡瀹屾垚鍚勭宸ヤ綔鑰屽垱閫狅紝鐢ㄦ埛鍒欎緷鎹畠鐨勮矗浠誨拰璧勬牸鏉ヨ鎸囨淳鐩稿簲鐨勮鑹詫紝鐢ㄦ埛鍙互寰堝鏄撳湴浠庝竴涓鑹茶鎸囨淳鍒板彟涓涓鑹層傝鑹插彲渚濇柊鐨勯渶姹傚拰緋葷粺鐨勫悎騫惰岃祴浜堟柊鐨勬潈闄愶紝鑰屾潈闄愪篃鍙牴鎹渶瑕佽屼粠鏌愯鑹蹭腑鍥炴敹銆傝鑹蹭笌瑙掕壊鐨勫叧緋誨彲浠ュ緩绔嬭搗鏉ヤ互鍥婃嫭鏇村箍娉涚殑瀹㈣鎯呭喌銆?/p> RBAC璁や負鏉冮檺鎺堟潈瀹為檯涓婃槸Who銆乄hat銆丠ow鐨勯棶棰樸傚湪RBAC妯″瀷涓紝who銆亀hat銆乭ow鏋勬垚浜嗚闂潈闄愪笁鍏冪粍,涔熷氨鏄?#8220;Who瀵筗hat(Which)榪涜How鐨勬搷浣?#8221;銆?銆銆<br /> Who錛氭潈闄愮殑鎷ョ敤鑰呮垨涓諱綋錛堝Principal銆乁ser銆丟roup銆丷ole銆丄ctor絳夌瓑錛?銆銆<br /> What錛氭潈闄愰拡瀵圭殑瀵硅薄鎴栬祫婧愶紙Resource銆丆lass錛夈?銆銆<br /> How錛氬叿浣撶殑鏉冮檺錛圥rivilege,姝e悜鎺堟潈涓庤礋鍚戞巿鏉冿級銆?銆銆Operator錛氭搷浣溿傝〃鏄庡What鐨凥ow鎿嶄綔銆備篃灝辨槸Privilege+Resource 銆銆<br /> Role錛氳鑹詫紝涓瀹氭暟閲忕殑鏉冮檺鐨勯泦鍚堛傛潈闄愬垎閰嶇殑鍗曚綅涓庤澆浣?鐩殑鏄殧紱籙ser涓嶱rivilege鐨勯昏緫鍏崇郴. 銆銆<br /> Group錛氱敤鎴風粍錛屾潈闄愬垎閰嶇殑鍗曚綅涓庤澆浣撱傛潈闄愪笉鑰冭檻鍒嗛厤緇欑壒瀹氱殑鐢ㄦ埛鑰岀粰緇勩傜粍鍙互鍖呮嫭緇?浠ュ疄鐜版潈闄愮殑緇ф壙)錛屼篃鍙互鍖呭惈鐢ㄦ埛錛岀粍鍐呯敤鎴風戶鎵跨粍鐨勬潈     闄愩俇ser涓嶨roup鏄瀵瑰鐨勫叧緋匯侴roup鍙互灞傛鍖栵紝浠ユ弧瓚充笉鍚屽眰綰ф潈闄愭帶鍒剁殑瑕佹眰銆?銆銆<br /> RBAC鐨勫叧娉ㄧ偣鍦ㄤ簬Role鍜孶ser, Permission鐨勫叧緋匯傜О涓篣ser assignment(UA)鍜孭ermission assignment(PA).鍏崇郴鐨勫乏鍙充袱杈歸兘鏄疢any-to-Many鍏崇郴銆傚氨鏄痷ser鍙互鏈夊涓猺ole錛宺ole鍙互鍖呮嫭澶氫釜user銆?銆銆<br /> 鍑℃槸鐢ㄨ繃RDBMS閮界煡閬擄紝n:m 鐨勫叧緋婚渶瑕佷竴涓腑闂磋〃鏉ヤ繚瀛樹袱涓〃鐨勫叧緋匯傝繖UA鍜孭A灝辯浉褰撲簬涓棿琛ㄣ備簨瀹炰笂錛屾暣涓猂BAC閮芥槸鍩轟簬鍏崇郴妯″瀷銆?銆銆Session鍦≧BAC涓槸姣旇緝闅愭櫐鐨勪竴涓厓绱犮傛爣鍑嗕笂璇達細姣忎釜Session鏄竴涓槧灝勶紝涓涓敤鎴峰埌澶氫釜role鐨勬槧灝勩傚綋涓涓敤鎴鋒縺媧諱粬鎵鏈夎鑹茬殑涓涓瓙闆嗙殑鏃跺欙紝寤虹珛涓涓猻ession銆傛瘡涓猄ession鍜屽崟涓殑user鍏寵仈錛屽茍涓旀瘡涓猆ser鍙互鍏寵仈鍒頒竴鎴栧涓猄ession. 銆銆<br /> 鍦≧BAC緋葷粺涓紝User瀹為檯涓婃槸鍦ㄦ壆婕旇鑹?Role)錛屽彲浠ョ敤Actor鏉ュ彇浠ser錛岃繖涓兂娉曟潵鑷簬Business Modeling With UML涓涔ctor-Role妯″紡銆傝冭檻鍒板浜哄彲浠ユ湁鐩稿悓鏉冮檺錛孯BAC寮曞叆浜咷roup鐨勬蹇點侴roup鍚屾牱涔熺湅浣滄槸Actor銆傝孶ser鐨勬蹇靛氨鍏瘋薄鍒頒竴涓漢銆?銆銆<br /> 榪欓噷鐨凣roup鍜孏BAC錛圙roup-Based Access Control錛変腑鐨凣roup錛堢粍錛変笉鍚屻侴BAC澶氱敤浜庢搷浣滅郴緇熶腑銆傚叾涓殑Group鐩存帴鍜屾潈闄愮浉鍏寵仈錛屽疄闄呬笂RBAC涔熷熼壌浜嗕竴浜汫BAC鐨勬蹇點?銆銆<br /> Group鍜孶ser閮藉拰緇勭粐鏈烘瀯鏈夊叧錛屼絾涓嶆槸緇勭粐鏈烘瀯銆備簩鑰呭湪姒傚康涓婃槸涓嶅悓鐨勩傜粍緇囨満鏋勬槸鐗╃悊瀛樺湪鐨勫叕鍙哥粨鏋勭殑鎶借薄妯″瀷錛屽寘鎷儴闂紝浜猴紝鑱屼綅絳夌瓑錛岃屾潈闄愭ā鍨嬫槸瀵規娊璞℃蹇墊弿榪般傜粍緇囩粨鏋勪竴鑸敤Martin fowler鐨凱arty鎴栬矗浠繪ā寮忔潵寤烘ā銆?銆銆<br /> Party妯″紡涓殑Person鍜孶ser鐨勫叧緋伙紝鏄瘡涓狿erson鍙互瀵瑰簲鍒頒竴涓猆ser錛屼絾鍙兘涓嶆槸鎵鏈夌殑User閮芥湁瀵瑰簲鐨凱erson銆侾arty涓殑閮ㄩ棬Department鎴栫粍緇嘜rganization錛岄兘鍙互瀵瑰簲鍒癎roup銆傚弽涔婫roup鏈繀瀵瑰簲涓涓疄闄呯殑鏈烘瀯銆備緥濡傦紝鍙互鏈夊壇緇忕悊榪欎釜Group錛岃繖鏄浜烘湁鐩稿悓鑱岃矗銆?銆銆<br /> 寮曞叆Group榪欎釜姒傚康錛岄櫎浜嗙敤鏉ヨВ鍐沖浜虹浉鍚岃鑹查棶棰樺錛岃繕鐢ㄤ互瑙e喅緇勭粐鏈烘瀯鐨勫彟涓縐嶆巿鏉冮棶棰橈細渚嬪錛孉閮ㄩ棬鐨勬柊闂繪垜甯屾湜鎵鏈夌殑A閮ㄩ棬鐨勪漢閮借兘鐪嬨傛湁浜嗚繖鏍蜂竴涓狝閮ㄩ棬瀵瑰簲鐨凣roup錛屽氨鍙洿鎺ユ巿鏉冪粰榪欎釜Group銆? <img src ="http://www.tkk7.com/algz/aggbug/344009.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.tkk7.com/algz/" target="_blank">绱澏鈭忛鎻氣啑</a> 2011-02-10 10:29 <a href="http://www.tkk7.com/algz/articles/344009.html#Feedback" target="_blank" style="text-decoration:none;">鍙戣〃璇勮</a></div>]]></description></item></channel></rss> <footer> <div class="friendship-link"> <p>感谢您访问我们的网站,您可能还对以下资源感兴趣:</p> <a href="http://www.tkk7.com/" title="亚洲av成人片在线观看">亚洲av成人片在线观看</a> <div class="friend-links"> </div> </div> </footer> 主站蜘蛛池模板: <a href="http://118762.com" target="_blank">亚洲日韩一区二区三区</a>| <a href="http://srztw.com" target="_blank">亚洲人配人种jizz</a>| <a href="http://dghxm168.com" target="_blank">免费电视剧在线观看</a>| <a href="http://haichuanwangluo.com" target="_blank">国产亚洲人成网站观看</a>| <a href="http://ebanyou.com" target="_blank">中文字幕视频在线免费观看</a>| <a href="http://gzmcmy.com" target="_blank">国产亚洲一区二区三区在线不卡</a>| <a href="http://hnmeiankj.com" target="_blank">久香草视频在线观看免费</a>| <a href="http://av520av.com" target="_blank">免费又黄又爽又猛的毛片</a>| <a href="http://zhaosifuwang.com" target="_blank">视频一区二区三区免费观看</a>| <a href="http://xiaochidaquan.com" target="_blank">免费人成无码大片在线观看</a>| <a href="http://caobi97.com" target="_blank">成人a毛片视频免费看</a>| <a href="http://tlyyt.com" target="_blank">亚洲色一色噜一噜噜噜</a>| <a href="http://600c63.com" target="_blank">中文字幕无码免费久久9一区9 </a>| <a href="http://yzddcpj.com" target="_blank">久久久久久毛片免费播放</a>| <a href="http://7x966.com" target="_blank">亚洲综合一区二区精品导航 </a>| <a href="http://yixinbanks.com" target="_blank">免费看的成人yellow视频</a>| <a href="http://www-75044.com" target="_blank">亚洲AV日韩AV一区二区三曲</a>| <a href="http://7755ga.com" target="_blank">免费大黄网站在线观</a>| <a href="http://zzz477.com" target="_blank">三级网站在线免费观看</a>| <a href="http://wilbysec.com" target="_blank">久久99国产亚洲精品观看</a>| <a href="http://www-741.com" target="_blank">国产成人精品免费午夜app</a>| <a href="http://xieehuomh.com" target="_blank">一本色道久久88—综合亚洲精品</a>| <a href="http://nxeea.com" target="_blank">国产又大又黑又粗免费视频</a>| <a href="http://bjgjjrxy.com" target="_blank">搜日本一区二区三区免费高清视频 </a>| <a href="http://ydstbj.com" target="_blank">亚洲人成网站在线观看播放</a>| <a href="http://51ykz.com" target="_blank">香蕉成人免费看片视频app下载</a>| <a href="http://nxjyyj.com" target="_blank">亚洲国产高清在线精品一区 </a>| <a href="http://246210.com" target="_blank">永久免费AV无码国产网站</a>| <a href="http://caita88.com" target="_blank">国产亚洲午夜精品</a>| <a href="http://lcqkp.com" target="_blank">亚洲an天堂an在线观看</a>| <a href="http://www-8812.com" target="_blank">女性自慰aⅴ片高清免费</a>| <a href="http://avyjj.com" target="_blank">一个人免费播放在线视频看片</a>| <a href="http://kwknc.com" target="_blank">亚洲精品人成在线观看</a>| <a href="http://ttvv55.com" target="_blank">女人18毛片特级一级免费视频</a>| <a href="http://sxhengshan.com" target="_blank">乱爱性全过程免费视频</a>| <a href="http://88533066.com" target="_blank">亚洲精品欧洲精品</a>| <a href="http://jst-hosp.com" target="_blank">免费在线观看中文字幕</a>| <a href="http://qqc46.com" target="_blank">精品无码国产污污污免费网站</a>| <a href="http://747767.com" target="_blank">精品亚洲福利一区二区</a>| <a href="http://lijieedu.com" target="_blank">亚洲精品自产拍在线观看动漫</a>| <a href="http://gztzbj.com" target="_blank">欧洲美熟女乱又伦免费视频</a>| <script> (function(){ var bp = document.createElement('script'); var curProtocol = window.location.protocol.split(':')[0]; if (curProtocol === 'https') { bp.src = 'https://zz.bdstatic.com/linksubmit/push.js'; } else { bp.src = 'http://push.zhanzhang.baidu.com/push.js'; } var s = document.getElementsByTagName("script")[0]; s.parentNode.insertBefore(bp, s); })(); </script> </body>