03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

WebAppServer/deployedResources/monitor<br />

/WebAppServer/deployedResources/operator<br />

10.List the ACLs in Access Manager and check if you have all the console role<br />

ACLs and ACLs for each J2EE role in your application(s).<br />

pdadmin> acl list<br />

default-webseal<br />

default-root<br />

_WebAppServer_deployedResources_monitor_Admin_20_Console_ACL<br />

_WebAppServer_deployedResources_operator_Admin_20_Console_ACL<br />

default-gso<br />

itsobank<br />

itsobankURItestACL<br />

_WebAppServer_deployedResources_consultant_ACL<br />

_WebAppServer_deployedResources_configurator_Admin_20_Console_ACL<br />

default-policy<br />

_WebAppServer_deployedResources_accountant_ACL<br />

_WebAppServer_deployedResources_clerk_ACL<br />

default-config<br />

_WebAppServer_deployedResources_manager_ACL<br />

default-management<br />

_WebAppServer_deployedResources_administrator_Admin_20_Console_ACL<br />

_WebAppServer_deployedResources_allauthenticated_ACL<br />

default-replica<br />

11.You can check the details on one of the ACLs using the following command:<br />

pdadmin> acl show<br />

_WebAppServer_deployedResources_monitor_Admin_20_Console_ACL<br />

ACL Name: _WebAppServer_deployedResources_monitor_Admin_20_Console_ACL<br />

Description: Generated by the PDWAS Migration Tool<br />

Entries:<br />

User sec_master TcmdbsvaBl<br />

Group pdwas-admin Ti<br />

12.For further detials, check the objects which the ACL is attached to.<br />

pdadmin> acl find<br />

_WebAppServer_deployedResources_monitor_Admin_20_Console_ACL<br />

/WebAppServer/deployedResources/monitor/Admin Console<br />

For more information about the parameters and using the migration utility, refer<br />

to the original product documentation.<br />

After migration<br />

Once an application is migrated, its security is in the province of the enterprise<br />

security model and should be controlled using Access Manager, either Web<br />

Portal Manager or the pdadmin utility. This is especially true for the modification<br />

of existing roles or the creation of new roles.<br />

Chapter 12. Tivoli Access Manager 439

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!