10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The<br />

access<br />

control<br />

list<br />

(ACL)<br />

An<br />

access<br />

control<br />

list<br />

policy,<br />

or<br />

ACL<br />

policy,<br />

is<br />

the<br />

set<br />

of<br />

rules<br />

(permissions)<br />

that<br />

specifies<br />

the<br />

conditions<br />

necessary<br />

to<br />

per<strong>for</strong>m<br />

certain<br />

operations<br />

on<br />

that<br />

resource.<br />

ACL<br />

policy<br />

definitions<br />

are<br />

important<br />

components<br />

of<br />

the<br />

security<br />

policy<br />

established<br />

<strong>for</strong><br />

the<br />

secure<br />

domain.<br />

ACL<br />

policies,<br />

like<br />

all<br />

policies,<br />

are<br />

used<br />

to<br />

stamp<br />

an<br />

organization’s<br />

security<br />

requirements<br />

onto<br />

the<br />

resources<br />

represented<br />

in<br />

the<br />

protected<br />

object<br />

space.<br />

An<br />

ACL<br />

policy<br />

specifically<br />

controls:<br />

1.<br />

What<br />

operations<br />

can<br />

be<br />

per<strong>for</strong>med<br />

on<br />

the<br />

resource<br />

2.<br />

Who<br />

can<br />

per<strong>for</strong>m<br />

these<br />

operations<br />

An<br />

ACL<br />

policy<br />

is<br />

made<br />

up<br />

of<br />

one<br />

or<br />

more<br />

entries<br />

that<br />

include<br />

user<br />

and<br />

group<br />

designations<br />

and<br />

their<br />

specific<br />

permissions<br />

or<br />

rights.<br />

An<br />

ACL<br />

can<br />

also<br />

contain<br />

rules<br />

that<br />

apply<br />

to<br />

unauthenticated<br />

users.<br />

Protected<br />

object<br />

policies<br />

(POP)<br />

ACL<br />

policies<br />

provide<br />

the<br />

authorization<br />

service<br />

with<br />

in<strong>for</strong>mation<br />

to<br />

make<br />

a<br />

″yes″<br />

or<br />

″no″<br />

answer<br />

on<br />

a<br />

request<br />

to<br />

access<br />

a<br />

protected<br />

object<br />

and<br />

per<strong>for</strong>m<br />

some<br />

operation<br />

on<br />

that<br />

object.<br />

POP<br />

policies<br />

contain<br />

additional<br />

conditions<br />

on<br />

the<br />

request<br />

that<br />

are<br />

passed<br />

back<br />

to<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

Base<br />

and<br />

the<br />

resource<br />

manager<br />

(such<br />

as<br />

<strong>WebSEAL</strong>)<br />

along<br />

with<br />

the<br />

″yes″<br />

ACL<br />

policy<br />

decision<br />

from<br />

the<br />

authorization<br />

service.<br />

It<br />

is<br />

the<br />

responsibility<br />

of<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

and<br />

the<br />

resource<br />

manager<br />

to<br />

en<strong>for</strong>ce<br />

the<br />

POP<br />

conditions.<br />

The<br />

following<br />

tables<br />

list<br />

the<br />

available<br />

attributes<br />

<strong>for</strong><br />

a<br />

POP:<br />

En<strong>for</strong>ced<br />

by<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

Base<br />

POP<br />

Attribute<br />

Description<br />

Name<br />

Name<br />

of<br />

the<br />

policy.<br />

This<br />

becomes<br />

the<br />

<br />

in<br />

the<br />

pdadmin<br />

pop<br />

commands.<br />

Description<br />

Descriptive<br />

text<br />

<strong>for</strong><br />

the<br />

policy.<br />

This<br />

appears<br />

in<br />

the<br />

pop<br />

show<br />

command.<br />

Warning<br />

Mode<br />

Provides<br />

administrators<br />

a<br />

means<br />

to<br />

test<br />

ACL<br />

and<br />

POP<br />

policies.<br />

Audit<br />

Level<br />

Specifies<br />

type<br />

of<br />

auditing:<br />

all,<br />

none,<br />

successful<br />

access,<br />

denied<br />

access,<br />

errors.<br />

Time-of-Day<br />

<strong>Access</strong><br />

Day<br />

and<br />

time<br />

restrictions<br />

<strong>for</strong><br />

successful<br />

access<br />

to<br />

the<br />

protected<br />

object.<br />

En<strong>for</strong>ced<br />

by<br />

Resource<br />

<strong>Manager</strong><br />

(such<br />

as<br />

<strong>WebSEAL</strong>)<br />

POP<br />

Attribute<br />

Description<br />

Quality<br />

of<br />

Protection<br />

Specifies<br />

degree<br />

of<br />

data<br />

protection:<br />

none,<br />

integrity,<br />

privacy.<br />

IP<br />

Endpoint<br />

Authentication<br />

Method<br />

Policy<br />

Specifies<br />

authentication<br />

requirements<br />

<strong>for</strong><br />

access<br />

from<br />

members<br />

of<br />

external<br />

networks.<br />

Document<br />

Cache<br />

Control<br />

Specify<br />

caching<br />

instructions<br />

<strong>for</strong><br />

the<br />

handling<br />

of<br />

specific<br />

documents.<br />

4<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!