From: Serban Popescu Date: Tue, 5 Feb 2019 19:09:00 +0000 (-0500) Subject: Optionally disable client authentication X-Git-Tag: 1.4.1~42^2 X-Git-Url: https://gerrit.onap.org/r/gitweb?p=aai%2Fbabel.git;a=commitdiff_plain;h=132d44fe0ab811cde1a1f2ce0f594f1d8ffdacbf Optionally disable client authentication based on an env. variable, client authentication can be disabled Change-Id: Ifa3e5d109d0609e0836ddaea2c1183799252ddd3 Issue-ID: AAI-2132 Signed-off-by: Serban Popescu --- diff --git a/src/main/java/org/onap/aai/babel/BabelApplication.java b/src/main/java/org/onap/aai/babel/BabelApplication.java index 9cf1078..0b0285b 100644 --- a/src/main/java/org/onap/aai/babel/BabelApplication.java +++ b/src/main/java/org/onap/aai/babel/BabelApplication.java @@ -46,6 +46,11 @@ public class BabelApplication extends SpringBootServletInitializer { HashMap props = new HashMap<>(); String decryptedValue = keyStorePassword.startsWith(OBFS_PATTERN)? Password.deobfuscate(keyStorePassword) : keyStorePassword; props.put("server.ssl.key-store-password", decryptedValue); + + String requireClientAuth = System.getenv("REQUIRE_CLIENT_AUTH"); + props.put("server.ssl.client-auth", + Boolean.FALSE.toString().equalsIgnoreCase(requireClientAuth) ? "want" : "need"); + new BabelApplication().configure(new SpringApplicationBuilder(BabelApplication.class).properties(props)) .run(args); } diff --git a/src/main/resources/application.properties b/src/main/resources/application.properties index c9982d6..1f5d420 100644 --- a/src/main/resources/application.properties +++ b/src/main/resources/application.properties @@ -1,6 +1,5 @@ server.port=9516 server.ssl.key-store=${CONFIG_HOME}/auth/tomcat_keystore -server.ssl.client-auth=need server.contextPath=/services/babel-service