9 Replies Latest reply: Jun 28, 2012 2:35 PM by Justin Bertram RSS

    Enabling security for HornetQ

    Stian Thorgersen Novice

      I'm trying to enable security for HornetQ in AS7. I've changed the security constraints as documented in https://docs.jboss.org/author/display/AS7/Messaging+configuration, but this has made no difference and I'm still able to send/receive messages without supplying a username/password.

       

      Snippet from server config:

                  <security-settings>
                      <security-setting match="#">
                          <permission type="send" roles="myrole"/>
                          <permission type="consume" roles="myrole"/>
                          <permission type="createNonDurableQueue" roles="myrole"/>
                          <permission type="deleteNonDurableQueue" roles="myrole"/>
                      </security-setting>
                  </security-settings>
      

       

      I couldn't find any documentation on how to specify roles and users for HornetQ in AS7 so I tried the same approach as I used in AS6. By adding hornetq-roles.properties and hornetq-users.properties.

       

      standalone/configuration/hornetq-roles.properties:

      myrole=myuser
      

       

      standalone/configuration/hornetq-users.properties:

      myuser=mypassword