Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8511749
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 11, 20262026-06-11T04:05:34+00:00 2026-06-11T04:05:34+00:00

I’m working on a Java-based web app using Tomcat 7.0 as the application server.

  • 0

I’m working on a Java-based web app using Tomcat 7.0 as the application server. After the helpful responses to a prior question, I’ve decided to use bcrypt to securely store passwords in my HSQLDB. However Tomcat’s default Realm implementations can’t handle bcrypt, so I need to write my own; that’s the only reason I’m writing a custom realm though as in all other ways plain JDBCRealm would work. I’ve been googling and looking at examples and I’m rather confused on a couple of points.

First, should I extend RealmBase, or JDBCRealm? Most examples I found use RealmBase, but I’ve successfully been using JDBCRealm for the app up to this point (as it’s still in development I started off with storing the passwords in plaintext and just using JDBCRealm to handle authentication), and one answer to a question on Code Ranch recommended just extending that. I’m not exactly sure which methods I’d need to override in that case, though. Just the authenticate method, or something more? If did this would JDBCRealm still be able to handle and manage user roles, getPrincipal, and all that?

Second, in the CodeRanch example linked above, unless I’m missing something, the getPassword method seems to be returning the unencrypted password. Since I’m going to be using bcrypt that won’t be possible, and it seems kind of inadvisable anyway, I would think. In other examples like on this blog post, getPassword seems to just return the password directly from the database. So which way is correct? I can’t find what exactly getPassword is used for; the documentation doesn’t say. Will it be ok to just return the encrypted value stored in the database for this?

If anybody can tell me what class I should extend, what methods I should override, and what getPassword should return, I would really appreciate it.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-11T04:05:36+00:00Added an answer on June 11, 2026 at 4:05 am

    Well after some trial and error I figured out how to do this. I extended JDBCRealm and only overrode the authenticate method and it works perfectly. I put BCrypt.java in the same directory as my custom realm, and this code is what worked:

    import java.security.Principal;
    import org.apache.catalina.realm.JDBCRealm;
    public class BCryptRealm extends JDBCRealm
    {
      @Override
      public Principal authenticate(String username, String credentials)
      {
        String hashedPassword = getPassword(username);
        // Added this check after discovering checkpw generates a null pointer
        // error if the hashedPassword is null, which happens when the user doesn't
        // exist. I'm assuming returning null immediately would be bad practice as
        // it would let an attacker know which users do and don't exist, so I added
        // a call to hashpw. No idea if that completely solves the problem, so if
        // your application has more stringent security needs this should be
        // investigated further.
        if (hashedPassword == null)
        {
          BCrypt.hashpw("fakePassword", BCrypt.gensalt());
          return null;
        }
        if (BCrypt.checkpw(credentials, hashedPassword))
        {
          return getPrincipal(username);
        }
        return null;
      }
    }
    

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

That's pretty much it. I'm using Nokogiri to scrape a web page what has
We're building an app, our first using Rails 3, and we're having to build
I have thousands of HTML files to process using Groovy/Java and I need to
I would like my Web page http://www.gmarks.org/math_in_e-mail.txt on my Apache 2.2.14 server to display
I am using Paperclip to handle profile photo uploads in my app. They upload
link Im having trouble converting the html entites into html characters, (&# 8217;) i
For some reason, after submitting a string like this Jack’s Spindle from a text
I have a string like this: La Torre Eiffel paragonata all’Everest What PHP function
I am reading a book about Javascript and jQuery and using one of the
I'm using v2.0 of ClassTextile.php, with the following call: $testimonial_text = $textile->TextileRestricted($_POST['testimonial']); ... and

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.