13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

It is possible to set up a hierachy of access based on the representation of theWeb Server’s resources in the Tivoli Access Manager Object Space. Rights andpermissions cascade within the space and so each higher level will haveincreasingly more generic protection but it is mandatory that any group or userbe given access at the lowest level, for example the resource must also bepresented in an entry within any other ACLs higher in the object space. In thisexample, if the entry for accountantgrp is removed from the ITSOBANK attachedto the object /WebSEAL/wsl01/itsobankURItest, from the previous sample, thenany attempt by accountant01 to access a resource deeper in the object space,here /WebSEAL/wsl01/itsobankURItest/itsobank/index.jsp, despite theitsobankURItestACL attached to this object, will fail, because the Transverseright for accountantgrp group is discontinuous at the higher level.12.6 Scenario 3: Tivoli’s <strong>WebSphere</strong> plug-inThis scenario documents how to use the <strong>WebSphere</strong> plug-in from Tivoli AccessManager to control <strong>WebSphere</strong> security from Tivoli Access Manager.12.6.1 Access Manager For <strong>WebSphere</strong> Application ServerAn extension of Access Manager Version 3.9 provides container-basedauthorization and centralized policy management for <strong>IBM</strong> <strong>WebSphere</strong>Application Server applications. Effectively, Access Manager provides a J2EEAuthorization Module which, when installed correctly, replaces <strong>WebSphere</strong>’s ownsecurity for user role-based authorization decisions.Chapter 12. Tivoli Access Manager 431

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!