Single Sign On from the Operating System

· Java

If I needed to encrypt data over the network or into the hard-drive, nothing would be easier, right? Using javax.crypto's and java.security's interfaces and classes to encrypt the data (assuming I have clearOs as the OutputStream I want to encrypt): Cipher c = Cipher.getInstance("DES/CBC/PKCS5Padding"); c.init(Cipher.ENCRYPT_MODE, key); OutputStream cipherOs = new CipherOutputStream(clearOs, c); Now I can use cipherOs to send the data, and every byte will be encoded using the provided key and the provided algorithm (which should be read from a configuration file). But where did this key come from? There are a few methods, some of them more secure (like certificates or JAAS identification) and some are less (like a hard-coded key in your java class). What I'm trying to do is use the already logged on user's credentials to encrypt the data. For example, if the user is identified using a Kerberos token in an Active Directory environment, the information in it (the type that doesn't change unless the password was changed) could be used as a key. If under a Unix system with default login, the hashed password could be retrieved and used. Is that even possible? Is there an API to do that?