22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

minimum permissions are granted to a user by name rather than group<br />

membership.<br />

Initial access control settings<br />

The Access Control List portlet defines access rights after the portal is running.<br />

However, during WebSphere Portal Server installation, initial access rights are<br />

assigned for the portal administrator and several user groups. Unless a new<br />

portal administrator name and password was created during installation, the<br />

default portal administrator is wpsadmin in the user group wpsadmins.<br />

If the Standard installation was selected and then the LDAP settings were<br />

customized, it is then possible to substitute another user for the wpsadmin user.<br />

However, that user must have a password and exist in LDAP prior to the<br />

installation. The wpsadmins user group can also be changed if the group to be<br />

substituted already exists in LDAP. If a decision is made to change the<br />

administrator or administrators user group, it is necessary to choose the<br />

Standard installation option and then choose to customize your LDAP settings<br />

and supply the necessary user and user group information when prompted by<br />

Setup Manager. When the database is first initialized, permissions for the portal<br />

administrator and administrator group are set to MANAGE PORTAL, giving these<br />

users full control over the portal.<br />

WebSphere Portal Server also configures permissions defined in a portal<br />

configuration XML file for initial portal use. The portal administrator and<br />

administrator group have MANAGE and DELEGATE on all configured portal<br />

resources. VIEW access is set for all authenticated users. Anonymous users<br />

have VIEW access to any resource that is part of the Welcome page. It is<br />

possible to modify these access rights or assign new access rights using the<br />

Access Control List portlet.<br />

Note: The portal administrator and administrator group do not have MANAGE<br />

access for users or groups by default.<br />

Subadministrators<br />

To grant access to a resource to a user, it is necessary to have DELEGATE<br />

access rights for the resource and DELEGATE access rights for the user or for<br />

the user group of which the user is a member. Portal Server supports unlimited<br />

levels of delegation. For example, administrators can create an unlimited number<br />

of subadministrators who can also create an unlimited number of<br />

sub-subadministrators.<br />

External security managers<br />

WebSphere Portal Server gives you the ability to move the access control for<br />

resource instances, such as specific portlets, to an external security manager. At<br />

Chapter 12. Security features of other Lotus products 565

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!