10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

The<br />

security<br />

policy<br />

To<br />

provide<br />

suitable<br />

security<br />

to<br />

Web<br />

resources,<br />

while<br />

retaining<br />

an<br />

easy-to-use<br />

system,<br />

the<br />

<strong>business</strong><br />

has<br />

established<br />

the<br />

following<br />

security<br />

goals:<br />

v<br />

Travel<br />

agent<br />

staff<br />

have<br />

complete<br />

control<br />

over<br />

all<br />

bookings.<br />

v<br />

Authenticated<br />

customers<br />

can<br />

make<br />

and<br />

change<br />

their<br />

own<br />

bookings,<br />

but<br />

cannot<br />

interfere<br />

with<br />

the<br />

travel<br />

data<br />

of<br />

other<br />

authenticated<br />

customers.<br />

v<br />

<strong>Administration</strong><br />

staff<br />

have<br />

complete<br />

access<br />

to<br />

all<br />

of<br />

the<br />

administration<br />

in<strong>for</strong>mation.<br />

v<br />

Travel<br />

Kingdom<br />

staff<br />

other<br />

than<br />

the<br />

<strong>Administration</strong><br />

department<br />

can<br />

change<br />

their<br />

own<br />

resume<br />

in<strong>for</strong>mation<br />

and<br />

view<br />

partial<br />

in<strong>for</strong>mation<br />

of<br />

other<br />

members<br />

of<br />

staff.<br />

Dynamic<br />

URL<br />

to<br />

object<br />

space<br />

mappings<br />

To<br />

achieve<br />

the<br />

security<br />

goals<br />

described<br />

above,<br />

the<br />

mappings<br />

from<br />

dynamic<br />

URLs<br />

to<br />

ACL<br />

object<br />

entries<br />

need<br />

to<br />

be<br />

configured<br />

as<br />

shown<br />

in<br />

the<br />

following<br />

table.<br />

Remember<br />

that<br />

the<br />

ordering<br />

of<br />

these<br />

mappings<br />

is<br />

an<br />

important<br />

part<br />

of<br />

achieving<br />

the<br />

security<br />

goals<br />

discussed<br />

earlier.<br />

Object<br />

Space<br />

Entry<br />

URL<br />

Pattern<br />

/ows/tr/browse<br />

/ows/db-apps/owa/tr.browse\?dest=*&date=??/??/????<br />

/ows/tr/auth<br />

/ows/db-apps/owa/tr.book\?dest=*&depart=??/??/????&<br />

return=??/??/????<br />

/ows/tr/auth<br />

/ows/db-apps/owa/tr.change<br />

/ows/admin/<strong>for</strong>all<br />

/ows/db-apps/owa/admin.resume<br />

/ows/admin/<strong>for</strong>all<br />

/ows/db-apps/owa/admin.browse\?empid=[th]???<br />

/ows/admin/auth<br />

/ows/db-apps/owa/admin.update\?empid=????<br />

Secure<br />

clients<br />

Client<br />

authenticate<br />

to<br />

<strong>WebSEAL</strong><br />

over<br />

a<br />

secure,<br />

encrypted<br />

channel.<br />

Customers<br />

who<br />

wish<br />

to<br />

use<br />

the<br />

Web<br />

interface<br />

must<br />

additionally<br />

register<br />

with<br />

the<br />

Travel<br />

Kingdom<br />

Webmaster<br />

to<br />

receive<br />

an<br />

account.<br />

Account<br />

and<br />

group<br />

structure<br />

Four<br />

groups<br />

are<br />

created<br />

on<br />

the<br />

system:<br />

Staff<br />

Members<br />

of<br />

the<br />

Travel<br />

Kingdom<br />

organization.<br />

TKStaff<br />

Travel<br />

Kingdom<br />

travel<br />

agents.<br />

AdminStaff<br />

Members<br />

of<br />

the<br />

Travel<br />

Kingdom<br />

<strong>Administration</strong><br />

Department.<br />

Note<br />

that<br />

<strong>Administration</strong><br />

staff<br />

members<br />

are<br />

also<br />

in<br />

the<br />

Staff<br />

group.<br />

Customer<br />

Customers<br />

of<br />

Travel<br />

Kingdom<br />

who<br />

want<br />

to<br />

make<br />

their<br />

travel<br />

bookings<br />

across<br />

the<br />

Internet.<br />

Each<br />

user<br />

is<br />

given<br />

an<br />

account<br />

in<br />

the<br />

secure<br />

domain<br />

to<br />

be<br />

individually<br />

identified<br />

by<br />

the<br />

<strong>WebSEAL</strong><br />

server.<br />

The<br />

user’s<br />

identity<br />

is<br />

also<br />

passed<br />

to<br />

the<br />

Oracle<br />

Web<br />

Servers<br />

to<br />

provide<br />

a<br />

single<br />

sign-on<br />

solution<br />

to<br />

all<br />

of<br />

the<br />

Web<br />

resources.<br />

<strong>Access</strong><br />

control<br />

The<br />

following<br />

table<br />

lists<br />

the<br />

access<br />

controls<br />

resulting<br />

from<br />

application<br />

of<br />

the<br />

preceding<br />

in<strong>for</strong>mation:<br />

354<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!