I finally got to porting Waffle to pure java with JNA. This means you don’t need .NET framework or COM to call Waffle from Java. It’s pure Java.
Waffle is a thin interface that simplifies Windows authentication and authorization, therefore providing a practical and workable back-end for NTLM, Negotiate, Kerberos and other SPNEGOs. Here’re some scenarios that you can now do without any headache directly in Java.
Logon a user: get his local and domain groups
This calls Win32 LogonUser, examines the user token and extracts all local and domain group memberships from it. This obviously includes nested groups.
Here’re the first lines of output for my current user:
User identity: dblock-green\dblock
NT AUTHORITY\NETWORK (S-1-5-2)
Active directory: get the list of trusted domains
The typical scenario is presenting a dropdown in front of the user to choose domains he can logon to. This list includes the current domain and all domain trusts.
Active directory: is this computer joined to a domain?
For systems that run both with and without active directory you need to programmatically figure out whether a computer is joined to a domain or a workgroup. If it’s joined to a domain or a workgroup you want to know what domain the computer is joined to.
Local machine: enumerate local groups
Negotiate: single sign-on
This is the sweetest waffle, both the client and the server-side of the Negotiate protocol made super easy. You would typically split this code in two halves and do the work of transmitting the tokens between client and server. In the end, the user is logged on to the server side and you can examine his local and domain groups.
Integration and Download
Waffle now has the same (or very similar) interface in C#, COM, Jacob and pure Java. So you can use it in a variety of applications. For COM we supply a merge module for your installer. For C#, reference Waffle.Windows.AuthProvider.dll. For Java, reference waffle-jna-auth.jar and include jna.jar and platform.jar in your distribution.