Assigning Policies To Protected Resources - Novell ACCESS MANAGER 3.1 SP1 - AGENT GUIDE Manual

J2ee* agent guide
Table of Contents

Advertisement

7.2.3 Assigning Policies to Protected Resources

After creating the Authorization policies, you need to create protected resources for the payroll
application, then assign the policies to the protected resources.
"Assigning the Authorization Policies to Protected Web Resources" on page 93
"Assigning the Authorization Policies to Protected EJB Resources" on page 94
Assigning the Authorization Policies to Protected Web Resources
To allow the J2EE Agent to enforce authorization for the payroll Web module, you need to create
three protected resources for the payroll application.
1 Click Devices > J2EE Agents > Edit.
2 In the Access Control Configuration section, deselect Enforce application server policy, select
Enforce additional authorization policy, then click Manage authorization policies.
3 Click New, specify the name of the payroll
the Type, then click OK.
4 Click New to create the required protected resources.
The manager protected resource has
PayrollWebManager Authorization policy. This policy allows only managers to access the
manager pages. Everyone else is denied access.
The myinfo protected resource has
Both the PayrollWebEmployee and PayrollWebManager Authorization policies are enabled for
this resource. This allows both employees and managers to view their own information pages.
The public protected resource uses
policy. This allows everyone who can log in to the Identity Server to have access to the public
pages of the application.
5 To save your changes, click Configuration Panel, then click OK.
6 On the J2EE Agents page, click Update.
file (
.war
PayrollWeb.war
as its URL path and enables the
/manager/*
and
/myInformation.jsp
for its URL path and is not assigned an Authorization
/*
Deploying the Sample Payroll Application
), select Web Module as
as its URL paths.
/payserv
93

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the ACCESS MANAGER 3.1 SP1 - AGENT GUIDE and is the answer not in the manual?

This manual is also suitable for:

Access manager 3.1 sp 1

Table of Contents