29.01.2013 Views

WebSphere Application Server V7.0: Concepts ... - IBM Redbooks

WebSphere Application Server V7.0: Concepts ... - IBM Redbooks

WebSphere Application Server V7.0: Concepts ... - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

d. On the Integrated Solutions Console, click the Configure button and add<br />

two custom properties:<br />

usersFile = c:\users.txt<br />

groupsFile = c:\groups.txt<br />

e. In the Global security panel, click Set as current.<br />

2. Enable application security. In the Global security panel, set Enable<br />

application security.<br />

3. Add a security domain and set its scope to application servers by performing<br />

the following steps:<br />

a. Click Security → Security domain.<br />

b. Add a new domain named ApplSecurity.<br />

c. In the new domain settings, select the Customize for this domain and<br />

Local operating system check boxes. In the configuration for this registry,<br />

introduce a name for it: ApplRealm.<br />

d. Set the scope of this domain to include the two clusters. Select ASCluster<br />

and MyEJBCluster.<br />

4. Add a new Windows user account on servers C and D. It will be used to log<br />

into the application.<br />

5. Assign administrative roles.<br />

The user account being used to log onto the BeenThere application needs an<br />

administrative role, otherwise the application will not work. This is because<br />

the application needs to get the node name from <strong>WebSphere</strong> <strong>Application</strong><br />

<strong>Server</strong> and, therefore, the monitor role is enough. To assign this role to the<br />

user, perform the following steps:<br />

a. Click Global security → Administrative user roles.<br />

b. Select ApplRealm, because this is the realm defined to be used by the<br />

application, and add the user to the list of mapped roles.<br />

6. Assign application roles.<br />

This application has a role (administrator) that has to be assigned to the user.<br />

Perform the following steps to assign application roles:<br />

a. Click <strong>Application</strong>s → <strong>Application</strong> types → <strong>WebSphere</strong> enterprise<br />

applications.<br />

b. Select BeenThere and click Security role to user / group mapping.<br />

c. Map the user from the ApplRealm to the administrator role.<br />

7. Restart application servers.<br />

<strong>Server</strong>s in the scope of the new security domain have to be restarted in order<br />

to get the new configuration settings.<br />

512 <strong>WebSphere</strong> <strong>Application</strong> <strong>Server</strong> <strong>V7.0</strong>: <strong>Concepts</strong>, Planning, and Design

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!