13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

►Session, entity, and message-driven bean methods can be delegated toexecute under the identity of either the caller (default), the EJB server, or aspecific security role. This is referred to as the Delegation Policy or Run-AsMode Mapping.In the next sections, each of these methods of applying security to EJBs will bediscussed in detail.5.2 Defining J2EE roles for EJB modulesThe method for defining security roles for EJBs and Web Components in theApplication Assembly Tool is the same. For example, to add a role namedmanager to the EJB component, do the following:1. Open the .ear file of the application, in our example: itsobank.ear.2. Open the EJB Modules folder for your application, open the desired moduleunder it, itsobankEJB in our case, then finally select <strong>Security</strong> Roles.3. If no security roles have previously been defined for EJBs, the box on theright will be empty. Right-click the space under Name, and you will see thepop-up menu. Select New to create a new security role.4. In the New <strong>Security</strong> Role dialog, shown in Figure 5-1, enter the name of therole, Manager, and (optionally) a description of the role.Figure 5-1 Application Assembly Tool - New <strong>Security</strong> Role dialog box5. Click Apply if you wish to add more security roles to the EJB component, orclick OK to close the New <strong>Security</strong> Role dialog box.Chapter 5. Securing EJBs 75

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!