10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Overview<br />

of<br />

ADI<br />

retrieval<br />

The<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

authorization<br />

rules<br />

evaluator<br />

per<strong>for</strong>ms<br />

authorization<br />

decisions<br />

based<br />

on<br />

Boolean<br />

logic<br />

applied<br />

to<br />

specific<br />

access<br />

decision<br />

in<strong>for</strong>mation<br />

(ADI).<br />

Detailed<br />

in<strong>for</strong>mation<br />

on<br />

the<br />

construction<br />

of<br />

authorization<br />

rules<br />

(using<br />

Boolean<br />

logic)<br />

and<br />

authorization<br />

decision<br />

in<strong>for</strong>mation<br />

(ADI)<br />

can<br />

be<br />

found<br />

in<br />

the<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

Base<br />

<strong>Administration</strong><br />

Guide.<br />

ADI<br />

required<br />

<strong>for</strong><br />

rules<br />

evaluation<br />

can<br />

be<br />

retrieved<br />

from<br />

the<br />

following<br />

sources:<br />

v<br />

Authorization<br />

decision<br />

parameters<br />

provided<br />

to<br />

the<br />

authorization<br />

rule<br />

as<br />

ADI<br />

by<br />

the<br />

authorization<br />

service<br />

Parameters<br />

include<br />

the<br />

target<br />

resource<br />

(protected<br />

object)<br />

and<br />

the<br />

requested<br />

action<br />

on<br />

the<br />

resource.<br />

Refer<br />

to<br />

the<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

Base<br />

<strong>Administration</strong><br />

Guide<br />

<strong>for</strong><br />

further<br />

in<strong>for</strong>mation<br />

on<br />

this<br />

topic.<br />

v<br />

The<br />

user<br />

credential<br />

The<br />

user<br />

credential<br />

is<br />

always<br />

included<br />

with<br />

the<br />

function<br />

call<br />

to<br />

the<br />

authorization<br />

rules<br />

evaluator,<br />

so<br />

it<br />

is<br />

immediately<br />

available.<br />

v<br />

The<br />

resource<br />

manager<br />

environment<br />

(application<br />

context)<br />

A<br />

resource<br />

manager,<br />

such<br />

as<br />

<strong>WebSEAL</strong>,<br />

can<br />

be<br />

configured<br />

to<br />

provide<br />

ADI<br />

from<br />

its<br />

own<br />

environment.<br />

For<br />

example,<br />

<strong>WebSEAL</strong><br />

has<br />

the<br />

capability<br />

to<br />

provide<br />

ADI<br />

contained<br />

in<br />

parts<br />

of<br />

the<br />

client<br />

request.<br />

A<br />

special<br />

prefix<br />

is<br />

used<br />

in<br />

the<br />

authorization<br />

rule<br />

to<br />

″trigger″<br />

this<br />

type<br />

of<br />

ADI<br />

source.<br />

v<br />

An<br />

external<br />

source<br />

through<br />

the<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

attribute<br />

retrieval<br />

service<br />

ADI<br />

can<br />

be<br />

obtained<br />

externally<br />

through<br />

the<br />

attribute<br />

retrieval<br />

service.<br />

A<br />

call<br />

is<br />

made<br />

to<br />

the<br />

attribute<br />

retrieval<br />

service<br />

through<br />

the<br />

resource<br />

manager’s<br />

entitlement<br />

service.<br />

ADI<br />

from<br />

the<br />

external<br />

source<br />

is<br />

returned<br />

in<br />

XML<br />

<strong>for</strong>mat<br />

to<br />

the<br />

authorization<br />

rules<br />

evaluator.<br />

358<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!