10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

ows/tr/browse<br />

unauthenticated<br />

Tr<br />

any_authenticated<br />

Tr<br />

/ows/tr/auth<br />

unauthenticated<br />

-<br />

any_other<br />

-<br />

group<br />

TKStaff<br />

Tr<br />

group<br />

Customer<br />

PTr<br />

/ows/admin/<strong>for</strong>all<br />

unauthenticated<br />

-<br />

any_other<br />

-<br />

group<br />

Staff<br />

Tr<br />

/ows/admin/auth<br />

unauthenticated<br />

-<br />

any_other<br />

-<br />

group<br />

AdminStaff<br />

Tr<br />

Customers<br />

and<br />

TKStaff<br />

have<br />

the<br />

same<br />

privileges<br />

on<br />

the<br />

booking<br />

and<br />

travel<br />

plan<br />

maintenance<br />

objects,<br />

except<br />

that<br />

the<br />

customers<br />

must<br />

encrypt<br />

in<strong>for</strong>mation<br />

(privacy<br />

permission)<br />

to<br />

give<br />

them<br />

further<br />

security<br />

when<br />

submitting<br />

sensitive<br />

data<br />

(such<br />

as<br />

credit<br />

card<br />

in<strong>for</strong>mation)<br />

across<br />

the<br />

untrusted<br />

Internet.<br />

Conclusion<br />

This<br />

simple<br />

example<br />

illustrates<br />

the<br />

concepts<br />

of<br />

deploying<br />

a<br />

system<br />

capable<br />

of:<br />

v<br />

Securing<br />

sensitive<br />

in<strong>for</strong>mation<br />

v<br />

Authenticating<br />

users<br />

v<br />

Authorizing<br />

access<br />

to<br />

sensitive<br />

in<strong>for</strong>mation<br />

In<br />

addition,<br />

the<br />

identities<br />

of<br />

the<br />

authenticated<br />

users<br />

of<br />

the<br />

system<br />

are<br />

known<br />

to<br />

both<br />

the<br />

<strong>WebSEAL</strong><br />

and<br />

Oracle<br />

Web<br />

Servers,<br />

and<br />

are<br />

used<br />

to<br />

provide<br />

an<br />

auditable,<br />

single<br />

sign-on<br />

solution.<br />

Chapter<br />

12.<br />

Application<br />

integration<br />

355

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!