13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Important: Although this feature is commonly referred to as the Run-as Mode,it does not have any noticeable effect on the bean to which it is applied. Abean configured to run as a member of a given security role actually executesusing the identity of the caller. It is only when calling methods in other EJBsthat the run as mode applies. These methods are called using the delegatedidentity.5.5.1 Bean level delegationThe EJB 2.0 Specification defines delegation at the EJB bean level using the element which allows the application assembler to delegate allmethods of a given bean to run as a member of a specific security role. Atdeployment time, a real user that is a member of the specified role must bemapped to this role, through a process which is called run-as role mapping. Allcalls to other EJBs made by the delegated bean will be called using the identityof this mapped user.Run As Caller (Default)EJB1EJB2caller01identity=caller01identity=caller01Run As RoleRun AsMappingusername = caller02password = xxxxxxxRole01caller01EJB1Run As Role = Role01identity=caller01EJB2identity=caller02Figure 5-8 Run as Caller versus Run as Role84 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!