Interface Table Security; Outbound Router Handler Security; Object-Level Authorization - IBM BJ0NJML - Service And Asset Management Integration Manual

Integration guide
Table of Contents

Advertisement

Interface Table Security

Outbound Router Handler Security

Object-Level Authorization

Security
processObjectStructure(..)
routeData(..)
To run these methods, the caller must retrieve a valid UserInfo object and pass it
to the method to gain access to the secure layer.
A UserInfo object is a serialized object that contains user details (user, password,
locale, language, and time zone information). The system uses the UserInfo object
for security purposes.
The system uses Java RMI/JRMP. You can communicate to the system services by
using a secure version of JRMP protocol using SSL.
Interface tables use the default database authentication and authorization. If
authentication and authorization are in effect, external programs that read or
write to the interface tables must provide proper authorization. To read from and
write to the interface tables, the USERNAME and PASSWORD values are
configured for the endpoint that implements the interface table handler.
The outbound router handlers have support for authorization and confidentiality.
The enterprise bean, HTTP, JMS, Web service, and interface table handlers have
support for security.
The system provides object-level authorization based on the security
configuration set within the system. If an object or attribute is marked as read-
only or hidden, then inbound message data processing is limited to data object
queries. You cannot insert, update, or delete data in that object. The authorization
level for a business object and object attribute can be configured in the Data
Restrictions tab in the Security Groups application.
Except for standard services, integration messages are not processed according to
application-level authorization.
The authorization that is used for system users controls the standard service
authorization. A signature option can be assigned to a standard service to limit
authorization to the users or groups that have authorization for a selected option.
Interface Table Security
185

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents