Integration with IBM WebSphere Liberty
This section describes how to integrate Kron PAM Password Vault with IBM WebSphere Liberty using the Kron PAM JDBC Proxy Driver. The integration enables WebSphere to retrieve database credentials dynamically from Kron PAM Vault at runtime, ensuring that no static passwords are stored within configuration files.
WebSphere Application Server manages JDBC connections through configuration elements defined in its server.xml file. By introducing the Kron PAM Proxy Driver, credential handling becomes dynamic—the driver contacts Kron PAM Vault securely via HTTPS, retrieves the managed account credentials, and injects them into the connection request transparently.
Configuration Steps
- Server-Level Configuration: Define the required libraries, JDBC driver, and data source within the server.xml configuration file.
- Application Configuration: Declare the JNDI resource reference () in the application’s web.xml file.
- Code Usage: Access the data source from your Java application using standard JNDI lookup methods. Example:
Context initCtx = new InitialContext();
DataSource ds = (DataSource) initCtx.lookup("java:comp/env/jdbc/KronJDBCDriverDS");Configuration Guidelines
When using the Kron PAM Proxy Driver:
- Do not specify user or password properties inside <properties> blocks. These credentials are automatically retrieved from Kron PAM at runtime.
- The targetDriverClass property defines which native JDBC driver will be loaded in the background.
- All PAM communication occurs via HTTPS using the baseUrl and acc_token parameters.
PostgreSQL Configuration Example
The following is an example configuration for connecting to a PostgreSQL database using a credential fetched from Kron PAM.
<library id="PostgreSQL_Library">
<fileset dir="${shared.resource.dir}/lib/postgresql" includes="postgresql-42.7.3.jar com.kron.jdbc-1.0.0.jar"/>
</library>
<jdbcDriver id="PostgreSQL_Kron_Driver" libraryRef="PostgreSQL_Library"/>
<dataSource id="PostgreSQL_DataSource" jndiName="jdbc/PostgreSQLDS" jdbcDriverRef="PostgreSQL_Kron_Driver">
<properties
url="jdbc:kron:postgresql://db-server:5432/appdb?baseUrl=https://example.kronpam.com&acc_token=6adcb6af-b84c-4a4c-bfe3-e1d97d633f2b&acc_name=webapp_user&acc_path=/DBs"
targetDriverClass="org.postgresql.Driver"/>
</dataSource>- Driver Component: PostgreSQL JDBC Driver 42.7.3
- Supported Versions: PostgreSQL 9.4 and higher
MySQL Configuration Example
The following is an example configuration for connecting to a MySQL database using a credential fetched from Kron PAM.
<library id="MySQL_Library">
<fileset dir="${shared.resource.dir}/lib/mysql" includes="mysql-connector-j-8.2.0.jar com.kron.jdbc-1.0.0.jar"/>
</library>
<jdbcDriver id="MySQL_Kron_Driver" libraryRef="MySQL_Library"/>
<dataSource id="MySQL_DataSource" jndiName="jdbc/MySQLDS" jdbcDriverRef="MySQL_Kron_Driver">
<properties
url="jdbc:kron:mysql://mysql-host:3306/appdb?baseUrl=https://example.kronpam.com&acc_token=6adcb6af-b84c-4a4c-bfe3-e1d97d633f2b&acc_name=mysql_app_user&acc_path=/DBs/MySQL"
targetDriverClass="com.mysql.cj.jdbc.Driver"/>
</dataSource>- Driver Component: MySQL Connector/J 8.2.0
- Supported Versions: MySQL 5.7 and 8.0
Oracle Database Configuration Example
The following is an example configuration for connecting to an Oracle database using a credential fetched from Kron PAM.
<library id="Oracle_Library">
<fileset dir="${shared.resource.dir}/lib/oracle" includes="ojdbc8-21.5.0.0.jar com.kron.jdbc-1.0.0.jar"/>
</library>
<jdbcDriver id="Oracle_Kron_Driver" libraryRef="Oracle_Library"/>
<dataSource id="Oracle_DataSource" jndiName="jdbc/OracleDS" jdbcDriverRef="Oracle_Kron_Driver">
<properties
url="jdbc:kron:oracle:thin:@//oracle-host:1521/orclpdb?baseUrl=https://example.kronpam.com&acc_token=6adcb6af-b84c-4a4c-bfe3-e1d97d633f2b&acc_name=c##jdbcuser&acc_path=/DBs"
targetDriverClass="oracle.jdbc.driver.OracleDriver"/>
</dataSource>- Driver Component: Oracle JDBC Driver (ojdbc8-21.5.0.0.jar)
- Supported Versions: Oracle 11g R2 – 21c
Microsoft SQL Server Configuration Example
The following is an example configuration for connecting to an MsSQL database using a credential fetched from Kron PAM.
<library id="SQLServer_Library">
<fileset dir="${shared.resource.dir}/lib/sqlserver" includes="mssql-jdbc-6.2.1.jre7.jar com.kron.jdbc-1.0.0.jar"/>
</library>
<jdbcDriver id="SQLServer_Kron_Driver" libraryRef="SQLServer_Library"/>
<dataSource id="SQLServer_DataSource" jndiName="jdbc/SQLServerDS" jdbcDriverRef="SQLServer_Kron_Driver">
<properties
url="jdbc:kron:sqlserver://sql-host:1433;databaseName=AppDB?baseUrl=https://example.kronpam.com&acc_token=6adcb6af-b84c-4a4c-bfe3-e1d97d633f2b&acc_name=sql_app_user&acc_path=/DBs/SQLServer"
targetDriverClass="com.microsoft.sqlserver.jdbc.SQLServerDriver"/>
</dataSource>- Driver Component: Microsoft JDBC Driver for SQL Server
- Supported Versions: SQL Server 2012 – 2022
Verification
After saving the configuration and restarting WebSphere:
- Validate that the data source is listed as active in the WebSphere administrative console.
- Deploy a test application or use the WebSphere Data Source test utility to verify the connection.
- Review Kron PAM Vault logs to confirm successful credential retrieval via the API.
- Confirm that no credentials are stored within the server.xml configuration.