29.01.2013 Views

WebSphere Application Server V7.0: Concepts ... - IBM Redbooks

WebSphere Application Server V7.0: Concepts ... - IBM Redbooks

WebSphere Application Server V7.0: Concepts ... - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Fine-grained administrative security<br />

Fine-grained administrative security was introduced in <strong>WebSphere</strong> <strong>Application</strong><br />

<strong>Server</strong> V6.1, although it was only configurable with the wsadmin command tool.<br />

Fine-grained administrative security can grant access to each user role per<br />

resource instance instead of granting access to all of the resources in the cell,<br />

which allows a better separation of administrative duties.<br />

<strong>WebSphere</strong> <strong>Application</strong> <strong>Server</strong> <strong>V7.0</strong> includes new panels in the Integrated<br />

Solutions Console that simplify the fine-grained administrative security<br />

configuration.<br />

In order for a user ID to have administrative authority, it must be assigned to one<br />

of the following roles:<br />

► Monitor<br />

The Monitor role has the least permissions. This role primarily confines the<br />

user to viewing the configuration and current state.<br />

► Configurator<br />

The Configurator role has the same permissions as the Monitor, and in<br />

addition, can change the configuration.<br />

► Operator<br />

The Operator role has Monitor permissions and can change the runtime state.<br />

For example, the Operator can start or stop services.<br />

► Administrator<br />

The Administrator role has the combined permissions of the Operator and<br />

Configurator and the permission required to access sensitive data, including<br />

server password, Lightweight Third Party Authentication (LTPA) password and<br />

keys, and so on.<br />

► ISC Admins<br />

An individual or group that uses the ISC Admins role has Administrator<br />

privileges for managing users and groups in the federated repositories from<br />

within the Integrated Solutions Console only.<br />

Note: The ISC Admins role is only available for Integrated Solutions<br />

Console users. It is not available for wsadmin users.<br />

► Deployer<br />

Users granted this role can perform both configuration actions and runtime<br />

operations on applications.<br />

394 <strong>WebSphere</strong> <strong>Application</strong> <strong>Server</strong> <strong>V7.0</strong>: <strong>Concepts</strong>, Planning, and Design

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!