<?xml version='1.0'?>
<!DOCTYPE policy PUBLIC
      "-//JBoss//DTD JBOSS Security Config 3.0//EN"
      "http://www.jboss.org/j2ee/dtd/security_config.dtd">

<policy>
    <!-- A template configuration for the jmx-console web application. This
      defaults to the UsersRolesLoginModule the same as other and should be
      changed to a stronger authentication mechanism as required.
    -->
    <application-policy name = "jbosstest-ssl">
       <authentication>
       <login-module code="org.jboss.security.auth.spi.BaseCertLoginModule"
          flag = "required">
          <module-option name="password-stacking">useFirstPass</module-option>
          <module-option name="securityDomain">java:/jaas/jbosstest-ssl</module-option>
       </login-module>
          <login-module code="org.jboss.security.auth.spi.UsersRolesLoginModule"
             flag = "required">
             <module-option name="password-stacking">useFirstPass</module-option>
             <module-option name="usersProperties">ssl-users.properties</module-option>
             <module-option name="rolesProperties">ssl-roles.properties</module-option>
             <module-option name="roleGroupSeperator">:</module-option>
          </login-module>
       </authentication>
    </application-policy>

</policy>

