10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>WebSEAL</strong>-specific<br />

ACL<br />

policies<br />

The<br />

following<br />

security<br />

considerations<br />

apply<br />

<strong>for</strong><br />

the<br />

/<strong>WebSEAL</strong><br />

container<br />

in<br />

the<br />

protected<br />

object<br />

space:<br />

v<br />

The<br />

<strong>WebSEAL</strong><br />

object<br />

begins<br />

the<br />

chain<br />

of<br />

ACL<br />

inheritance<br />

<strong>for</strong><br />

the<br />

<strong>WebSEAL</strong><br />

region<br />

of<br />

the<br />

object<br />

space<br />

v<br />

If<br />

you<br />

do<br />

not<br />

apply<br />

any<br />

other<br />

explicit<br />

ACLs,<br />

this<br />

object<br />

defines<br />

(through<br />

inheritance)<br />

the<br />

security<br />

policy<br />

<strong>for</strong><br />

the<br />

entire<br />

Web<br />

space<br />

v<br />

The<br />

traverse<br />

permission<br />

is<br />

required<br />

<strong>for</strong><br />

access<br />

to<br />

any<br />

object<br />

below<br />

this<br />

point<br />

Refer<br />

to<br />

the<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

Base<br />

Administrator’s<br />

Guide<br />

<strong>for</strong><br />

complete<br />

in<strong>for</strong>mation<br />

about<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

ACL<br />

policies.<br />

/<strong>WebSEAL</strong>/host-instance_name<br />

This<br />

sub-directory<br />

entry<br />

represents<br />

the<br />

beginning<br />

of<br />

the<br />

Web<br />

space<br />

<strong>for</strong><br />

a<br />

particular<br />

<strong>WebSEAL</strong><br />

server<br />

instance.<br />

The<br />

following<br />

security<br />

considerations<br />

apply<br />

<strong>for</strong><br />

this<br />

object:<br />

v<br />

The<br />

traverse<br />

permission<br />

is<br />

required<br />

<strong>for</strong><br />

access<br />

to<br />

any<br />

object<br />

below<br />

this<br />

point<br />

v<br />

If<br />

you<br />

do<br />

not<br />

apply<br />

any<br />

other<br />

explicit<br />

ACLs,<br />

this<br />

object<br />

defines<br />

(through<br />

inheritance)<br />

the<br />

security<br />

policy<br />

<strong>for</strong><br />

the<br />

entire<br />

object<br />

space<br />

on<br />

this<br />

machine<br />

/<strong>WebSEAL</strong>/host-instance_name/file<br />

This<br />

sub-directory<br />

entry<br />

represents<br />

the<br />

resource<br />

object<br />

checked<br />

<strong>for</strong><br />

HTTP<br />

access.<br />

The<br />

permissions<br />

checked<br />

depend<br />

on<br />

the<br />

operation<br />

being<br />

requested.<br />

<strong>WebSEAL</strong><br />

ACL<br />

permissions<br />

The<br />

following<br />

table<br />

describes<br />

the<br />

ACL<br />

permissions<br />

applicable<br />

<strong>for</strong><br />

the<br />

<strong>WebSEAL</strong><br />

region<br />

of<br />

the<br />

object<br />

space:<br />

Operation<br />

Description<br />

r<br />

read<br />

View<br />

the<br />

Web<br />

object<br />

x<br />

execute<br />

Run<br />

the<br />

CGI<br />

program.<br />

d<br />

delete<br />

Remove<br />

the<br />

Web<br />

object<br />

from<br />

the<br />

Web<br />

space.<br />

m<br />

modify<br />

PUT<br />

an<br />

HTTP<br />

object.<br />

(Place<br />

-<br />

publish<br />

-<br />

an<br />

HTTP<br />

object<br />

in<br />

the<br />

<strong>WebSEAL</strong><br />

object<br />

space.)<br />

l<br />

list<br />

Required<br />

by<br />

policy<br />

server<br />

to<br />

generate<br />

an<br />

automated<br />

directory<br />

listing<br />

of<br />

the<br />

Web<br />

space.<br />

This<br />

permission<br />

also<br />

governs<br />

whether<br />

a<br />

client<br />

can<br />

see<br />

the<br />

directory<br />

contents<br />

listing<br />

when<br />

the<br />

default<br />

″index.html″<br />

page<br />

is<br />

not<br />

present.<br />

g<br />

delegation<br />

Assigns<br />

trust<br />

to<br />

a<br />

<strong>WebSEAL</strong><br />

server<br />

to<br />

act<br />

on<br />

behalf<br />

of<br />

a<br />

client<br />

and<br />

pass<br />

requests<br />

to<br />

a<br />

junctioned<br />

<strong>WebSEAL</strong><br />

server.<br />

Default<br />

/<strong>WebSEAL</strong><br />

ACL<br />

policy<br />

Core<br />

entries<br />

<strong>for</strong><br />

the<br />

<strong>WebSEAL</strong><br />

ACL,<br />

default-webseal,<br />

include:<br />

Group<br />

iv-admin<br />

Tcmdbsvarxl<br />

Group<br />

webseal-servers<br />

Tgmdbsrxl<br />

User<br />

sec_master<br />

Tcmdbsvarxl<br />

Any-other<br />

Trx<br />

Unauthenticated<br />

T<br />

110<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!