03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Figure 10-3 Mapping a user to an Administrative role<br />

Mapping a group to an administrator role<br />

As mentioned earlier, it is advisable to map groups to roles rather than users.<br />

Mapping a group is similar to mapping a user.<br />

1. From the Admin Console, click System Administration -> Console Groups<br />

2. Click Add.<br />

3. Either a specific group or a special subject may be mapped.<br />

To map a specific group, enter the group name in the Specify group text box.<br />

This group must be defined in the user registry that will be active when Global<br />

<strong>Security</strong> is enabled.<br />

To map a special subject, select the Special subject option and the<br />

appropriate subject from the drop-down list. A special subject is a<br />

generalization of a particular class of users. The AllAuthenticated special<br />

subject means that the access check of the admin role ensures that the user<br />

making the request has at least been authenticated. The Everyone special<br />

subject means that anyone, authenticated or not, can perform the action, as if<br />

no security were enabled.<br />

4. Select the appropriate administrative role; more than one role may be<br />

selected.<br />

5. Click OK. If the group cannot be found in the registry, then an error will occur.<br />

6. Ensure the new mapping is in the Console Groups list.<br />

7. Save the change to the master configuration, using the link provided at the<br />

top of the window, and restart the server.<br />

Chapter 10. Administering <strong>WebSphere</strong> security 241

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!