13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Do not make changes to the deployment descriptors of an application from within<strong>WebSphere</strong>. They are not reflected in the EAR file and cannot be captured byAccess Manager. Thus it behooves you to ensure that if you are migratingexisting applications designed before the enterprise security model was in place,the EAR file you migrate accurately reflects the application’s current securityconfiguration.The migration of an EAR file to the Access Manager protected object spacecreates ACLs attached to those objects. If these ACLs are used elsewhere withinthe object space, they cannot be removed while attached to any object.12.7 Scenario 4: Using the aznAPIThe <strong>IBM</strong> Tivoli Access Manager Java runtime component includes a Javaversion of a subset of the Access Manager authorization API. The authorizationAPI consists of a set of classes and methods that provide Java applications withthe ability to interact with Access Manager to make authentication andauthorization decisions.Application developers should use the Javadoc information provided with theAccess Manager Application Developer Kit (ADK) to add Access Managerauthorization and security services to new or existing Java applications.The authorization API classes are installed as part of the Access Manager Javaruntime component. These classes communicate directly with the AccessManager authorization server by establishing an authenticated SSL session withthe authorization server process.Important: The aznAPI installs as the Application Development Kit of TivoliAccess Manager. When you use the ezinstall for Access Manager to install theproduct, it will not install the authorization API for you.In order to get the API installed on your system, you have to install it manuallyfrom the Tivoli Access Manager CD. You can find the install image calledPDJRTE, which installs the Java Runtime component for Tivoli AccessManager. On the Windows platform the PDJRTE is at:\windows\PolicyDirector\Disk Images\Disk1\PDJRTE.The aznAPI Java classes are basically Java wrappers for the original C API.440 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!