03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

It is possible to set up a hierachy of access based on the representation of the<br />

Web Server’s resources in the Tivoli Access Manager Object Space. Rights and<br />

permissions cascade within the space and so each higher level will have<br />

increasingly more generic protection but it is mandatory that any group or user<br />

be given access at the lowest level, for example the resource must also be<br />

presented in an entry within any other ACLs higher in the object space. In this<br />

example, if the entry for accountantgrp is removed from the ITSOBANK attached<br />

to the object /WebSEAL/wsl01/itsobankURItest, from the previous sample, then<br />

any attempt by accountant01 to access a resource deeper in the object space,<br />

here /WebSEAL/wsl01/itsobankURItest/itsobank/index.jsp, despite the<br />

itsobankURItestACL attached to this object, will fail, because the Transverse<br />

right for accountantgrp group is discontinuous at the higher level.<br />

12.6 Scenario 3: Tivoli’s <strong>WebSphere</strong> plug-in<br />

This scenario documents how to use the <strong>WebSphere</strong> plug-in from Tivoli Access<br />

Manager to control <strong>WebSphere</strong> security from Tivoli Access Manager.<br />

12.6.1 Access Manager For <strong>WebSphere</strong> Application Server<br />

An extension of Access Manager Version 3.9 provides container-based<br />

authorization and centralized policy management for <strong>IBM</strong> <strong>WebSphere</strong><br />

Application Server applications. Effectively, Access Manager provides a J2EE<br />

Authorization Module which, when installed correctly, replaces <strong>WebSphere</strong>’s own<br />

security for user role-based authorization decisions.<br />

Chapter 12. Tivoli Access Manager 431

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!