Server-level security settings

Use this page to enable server level security and specify other server level security configurations.

To view this administrative console page, click Servers > Application Servers > server > Server Security > Server Level Security.

 

Configuration tab

Enabled

Use this flag to disable or enable security again for this application server while global security is enabled. Server security is enabled by default when global security is enabled. You cannot enable security on an application server while global security is disabled. Administrative (administrative console and wsadmin) and naming security remain enabled while global security is enabled, regardless of the status of this flag.

Data type Boolean
Default Disable

Enforce Java 2 Security

Specifies that the server enforces Java 2 Security permission checking at the server level. When cleared, the Java 2 server-level security manager is not installed and all of the Java 2 Security permission checking is disabled at the server level.

If your application policy file is not set up correctly, see Configuring the was.policy file for information on how to configure an application policy file.

Data type Boolean
Default Disabled
Range Enabled or Disabled

Use Domain Qualified User IDs

Specifies whether user IDs returned by getUserPrincipal()-like calls are qualified with the server level security domain within which they reside.

Data type Boolean
Default Disabled
Range Enable or Disable

Cache Timeout

Specifies the timeout value for server level security cache in seconds.

Data type Integer
Units Seconds
Default 600
Range Greater than 30 seconds. Avoid setting cache timeout value to 30 seconds or less.

Issue Permission Warning

Specifies whether a warning is issued during application installation when an application requires a Java 2 permission that is normally not granted to an application.

WebSphere Application Server provides support for policy file management. A number of policy files are included in WebSphere Application Server. Some of these policy files are static and some of them are dynamic. Dynamic policy is a template of permissions for a particular type of resource. In dynamic policy files, the code bases are evaluated at run time using configuration data. You can add or remove permissions, as needed, for each code base. However, do not add, remove, or modify the existing code bases. The real code base is dynamically created from the configuration and run-time data. The filter.policy file contains a list of permissions that an application does not have, according to the J2EE 1.3 Specification. For more information on permissions, see Java 2 security policy files.

Data type Boolean
Default Enabled
Range Enable or Disable

Active Protocol

Specifies the active server level security authentication protocol when server level security is enabled.

You can use an Object Management Group (OMG) protocol called Common Secure Interoperability V2 (CSIv2) for more vendor interoperability and additional features. If all of the servers in your entire security domain are Version 5.0 servers, it is best to specify CSI as your protocol.

If some servers are V3.x or V4.x servers, it is best to specify CSI and SAS. However, by specifying CSI and SAS, you now have two interceptors invoking each request. However, by specifying CSI and SAS, you now have two interceptors invoking each request.

Data type String
Default CSI and SAS
Range CSI, CSI and SAS

Related tasks
Configuring the was.policy file