29.01.2013 Views

WebSphere Application Server V7.0: Concepts ... - IBM Redbooks

WebSphere Application Server V7.0: Concepts ... - IBM Redbooks

WebSphere Application Server V7.0: Concepts ... - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Scenario 3: Using a z/OS security product<br />

In this scenario, let us say that you want to enable administrative security during<br />

the profile creation process using a z/OS security product to manage security.<br />

With this option, each user and group identity corresponds to a user ID or group<br />

in the z/OS system SAF-compliant security system (<strong>IBM</strong> RACF or an equivalent<br />

product).<br />

Access to <strong>WebSphere</strong> <strong>Application</strong> <strong>Server</strong> roles is controlled using the SAF<br />

EJBROLE profile, and digital certificates for SSL communication are stored in the<br />

z/OS security product.<br />

Summary of options to enable security at profile creation<br />

Table 12-1 summarizes these options.<br />

Table 12-1 Options to enable security at profile creation<br />

Option chosen Implications<br />

Use <strong>WebSphere</strong> <strong>Application</strong> <strong>Server</strong> to manage<br />

user identities and the authorization policy.<br />

404 <strong>WebSphere</strong> <strong>Application</strong> <strong>Server</strong> <strong>V7.0</strong>: <strong>Concepts</strong>, Planning, and Design<br />

► Each <strong>WebSphere</strong> <strong>Application</strong> <strong>Server</strong> user and<br />

group identity corresponds to an entry in a<br />

<strong>WebSphere</strong> <strong>Application</strong> <strong>Server</strong> user registry.<br />

The initial registry is a file-based user registry,<br />

created during customization, and residing in<br />

the configuration file system.<br />

► Access to roles is controlled using <strong>WebSphere</strong><br />

<strong>Application</strong> <strong>Server</strong> role bindings. In particular,<br />

administrative roles are controlled using the<br />

Console users and groups settings in the<br />

administrative console.<br />

► Digital certificates for SSL communication are<br />

stored in the configuration file system.<br />

Do not enable security. No administrative security is configured. Anyone<br />

with network access to the administrative console<br />

port can make changes to the server or cell<br />

configuration.<br />

Use a z/OS security product to manage user<br />

identities and authorization policy (z/OS only).<br />

► Each <strong>WebSphere</strong> <strong>Application</strong> <strong>Server</strong> user and<br />

group identity corresponds to a user ID or<br />

group in the z/OS system SAF-compliant<br />

security system (RACF or an equivalent<br />

product).<br />

► Access to <strong>WebSphere</strong> <strong>Application</strong> <strong>Server</strong> roles<br />

is controlled using the SAF EJBROLE profile.<br />

► Digital certificates for SSL communication are<br />

stored in the z/OS security product.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!