29.01.2013 Views

WebSphere Application Server V7.0: Concepts ... - IBM Redbooks

WebSphere Application Server V7.0: Concepts ... - IBM Redbooks

WebSphere Application Server V7.0: Concepts ... - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

12.1 What is new in <strong>V7.0</strong><br />

This section describes the major new features added to <strong>WebSphere</strong> <strong>Application</strong><br />

<strong>Server</strong> <strong>V7.0</strong>.<br />

► Multiple security domains<br />

This feature provides the possibility of having different security settings in the<br />

same cell, therefore allowing separate security environments for<br />

administrative applications and user applications. A security domain can be<br />

enabled at cell, node, or application server scope.<br />

► Security auditing<br />

As a new subsystem of the <strong>WebSphere</strong> <strong>Application</strong> <strong>Server</strong> security<br />

infrastructure, security auditing achieves two primary objectives:<br />

– Confirming the effectiveness and integrity of the existing security<br />

configuration.<br />

– Identifying areas where improvement to the security configuration might<br />

be needed.<br />

► Certificate management enhancements<br />

New certificate management functions have been provided to improve the<br />

security of communications between a server and a client:<br />

– Creating and using a certificate authority (CA) client to enable users to<br />

connect to a CA server to request, query, and revoke certificates<br />

– Creating and using chained personal certificates to allow a certificate to be<br />

signed with a longer life span<br />

– Creating and revoking CA certificates to ensure secure communication<br />

between the CA client and the CA server<br />

– For <strong>WebSphere</strong> <strong>Application</strong> <strong>Server</strong> for z/OS, performing certificate<br />

management on System Authorization Facility (SAF) keyrings<br />

► Security annotations<br />

Security annotations, which are an alternative means of defining security<br />

roles and policies, can be used instead of, or in addition to, defining roles and<br />

policies in the deployment descriptor.<br />

► Fine-grained administrative security in the Integrated Solutions Console<br />

In addition to the existing support in the wsadmin command tool, fine-grained<br />

security can now be configured in the Integrated Solutions Console as well.<br />

380 <strong>WebSphere</strong> <strong>Application</strong> <strong>Server</strong> <strong>V7.0</strong>: <strong>Concepts</strong>, Planning, and Design

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!