13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

WebSEALAuthenticated Usersbefore forwardingrequests for protectedresources<strong>WebSphere</strong> Application ServerContainer integratedwith Access ManagerJ2EE ApplicationDeploymentDescriptorAccess Manager'sLDAP User RegistryAccess ManagerAuthorization ServerAccess Manager'sPolicy ServerFigure 12-24 Access Manager for <strong>WebSphere</strong> beta ModelWhen a user requests a protected resource, WebSEAL authenticates the useragainst the Access Manager user registry. Junction configuration defines thetype and number of credentials then forwarded to the application server.The container examines the request for access to a protected resource and fromthe J2EE application deployment descriptor, determines the required role that theuser must have to be granted authorization. The container then hands off to theintegrated Access Manager module.The Access Manager module requests an authorization decision from anAccess Manager authorization server which checks with its local replica of theAccess Manager policy database. Replicas are normally updated on a pull basisfrom the single Access Manager Policy Master within the <strong>Security</strong> Domain.While these calls can be made to a remote server, without the embedded AccessManager promised for the final <strong>WebSphere</strong> Application Server V5, performanceand scalability require that an Access Manager Authorization Server be installedon the same platform as <strong>WebSphere</strong>. Of course, this means that theperformance burden is passed to the platform hardware which must be capableof bearing both loads.Having returned the access decision, granted or denied, to the container,<strong>WebSphere</strong> then acts on it.432 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!