13.04.2013 Views

Digipass Plug-In for SBR Administrator Reference - Vasco

Digipass Plug-In for SBR Administrator Reference - Vasco

Digipass Plug-In for SBR Administrator Reference - Vasco

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Digipass</strong> <strong>Plug</strong>-<strong>In</strong> <strong>for</strong> <strong>SBR</strong> <strong>Administrator</strong> <strong>Reference</strong> ODBC Database<br />

3.6 Database User Accounts<br />

It is important to consider which database user accounts will be utilized when installing,<br />

running and administering <strong>Digipass</strong> <strong>Plug</strong>-<strong>In</strong> <strong>for</strong> <strong>SBR</strong>. There are a few main roles that need to<br />

be considered:<br />

Schema creator. A database user account is needed to create the tables used by<br />

<strong>Digipass</strong> <strong>Plug</strong>-<strong>In</strong> <strong>for</strong> <strong>SBR</strong>. Typically this would be either a fully privileged DBA account, or<br />

the account that will own the schema.<br />

Schema owner. This may be the same as the schema creator. If not, the schema<br />

creator can transfer ownership of the new tables after they have been created.<br />

<strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> account. This may be the same as the schema creator or owner, but as it<br />

does not need extensive permissions on the tables, you may prefer to use an account<br />

with less privileges.<br />

<strong>Administrator</strong> account. <strong>Administrator</strong>s may be allowed to log directly into the<br />

database in order to administer data. If so, the Adminstration MMC <strong>In</strong>terface will require<br />

a database user account with sufficient permissions to modify the data as required. It is<br />

not necessary to create a separate account, but you may prefer to do so, in order to<br />

control the permissions strictly. You may even create multiple administrator accounts<br />

with different permissions.<br />

A few elements need to be taken into account when setting up these various database user<br />

accounts.<br />

3.6.1 Permissions on the Tables<br />

The following permissions are required by the <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> and administrator accounts:<br />

Table 22: Table Permissions Required<br />

Table <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> <strong>Administrator</strong><br />

vdsControl SELECT, INSERT*, UPDATE* SELECT<br />

vdsUser SELECT, INSERT**, UPDATE SELECT, INSERT, UPDATE, DELETE***<br />

vdsUserAttr SELECT SELECT, INSERT, UPDATE, DELETE***<br />

vds<strong>Digipass</strong> SELECT, UPDATE SELECT, INSERT, UPDATE, DELETE***<br />

vdsDPApplication SELECT, UPDATE SELECT, INSERT, UPDATE, DELETE***<br />

vdsPolicy SELECT SELECT, INSERT, UPDATE, DELETE***<br />

vdsComponent SELECT SELECT, INSERT, UPDATE, DELETE***<br />

vdsBackEnd SELECT SELECT, INSERT, UPDATE, DELETE***<br />

vdsDomain SELECT SELECT, INSERT, UPDATE, DELETE***<br />

vdsOrgUnit SELECT SELECT, INSERT, UPDATE, DELETE***<br />

* The <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> does not need INSERT and UPDATE permission on the vdsControl table itself. However, when<br />

the <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> Configuration GUI is used to Configure Advanced Settings, the same database user account<br />

is used as the <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong>, and at this time the INSERT and UPDATE permissions are needed.<br />

** INSERT permission is only required when Dynamic User Registration is used.<br />

*** <strong>In</strong> general, SELECT permission is required on all tables, but you can restrict any of INSERT, UPDATE and DELETE<br />

permissions according to the restrictions you need to impose upon your administrators.<br />

© 2006 VASCO Data Security <strong>In</strong>c. 51

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!