22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

12.5.2 Authorization<br />

562 Lotus Security Handbook<br />

Credentials can take their input identity from the JAAS Subject Principals, from<br />

the portlet configuration, or from the credential vault service. Portlet writers can<br />

use the Credential Service to retrieve credentials from the Credential vault or the<br />

JAAS Subject. Credential Service objects can also be used to pass Tivoli Access<br />

Manager or SiteMinder single sign-on tokens from the JAAS subject to the<br />

back-end application in the appropriate headers.<br />

Credential Vault<br />

The Credential Vault is a portal service that aims to assist portlets and portal<br />

users in managing multiple identities. The Credential Vault stores credentials that<br />

allow portlets to log into applications outside the portal's realm on behalf of the<br />

user.<br />

The WebSphere Portal Server provides one simple database vault<br />

implementation for mappings to secrets for other enterprise applications. The<br />

Default Vault comes pre-configured with an administrator-managed vault<br />

segment and a user-managed vault segment. The user-managed vault allows<br />

users to add application definitions, such as a POP3 mail account, under the<br />

user vault and store a mapping there. Administrator-managed vaults allow users<br />

to update mappings; however, users may not add new applications to this vault.<br />

By default, the default vault loads an encryption exit which encodes the<br />

passwords using base64.<br />

It is possible to plug in additional administrator-managed vaults by writing a<br />

custom Vault Adapter for the specific vault. This should be done by editing the<br />

comments in this configuration file to specify Vault Adapter Implementations:<br />

was_root/lib/app/config/services/VaultServices.properties<br />

Note that plugged in vaults can be managed only by an administrator. After the<br />

vault has been plugged in, the portal should be restarted, and a Vault Segment<br />

added to the vault using the Credential Vault portlet.<br />

WebSphere Portal Server also supports the storage and retrieval of credentials<br />

from other vault services, such as Tivoli Access Manager. Portal Server ships a<br />

vault adapter plug-in for Tivoli Access Manager, which works on AIX, Solaris, and<br />

Windows. See the appropriate product documentation for information on<br />

installing the plug-in. For details on working with vaults, see Credential Vault<br />

help.<br />

Administrators configure access to portal resources throughout the portal by<br />

granting permissions to users and groups using the Access Control List portlet.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!