Network Deployment (Distributed operating systems), v8.0 > Reference > Sets > OSGi Applications administrative console panels


Security role to user or group mapping [Settings]

We can specify the users and groups that are mapped to the security roles used with the OSGi application.

To view this panel in the administrative console, click one of the following paths:

The Security role to user/group mapping option is only visible if the application uses security roles.

User and group mapping.
Button Resulting action
Map Users Lists the users that are mapped to the specified role within this application.
Map Groups Lists the groups that are mapped to this specified role within this application.
Map Special Subjects Map any of the following special subjects to a selected role:

  • All authenticated in application realm: All authenticated users that are in the applications realm, which specifies whether to map all the authenticated users to a specified role. When you map all authenticated users to a specified role, all the valid users in the current registry who have been authenticated can access resources that are protected by this role.

    This selection also applies to all authenticated users regardless of the realm.

  • All authenticated in trusted realms: This option is available only when multiple realms are used. All authenticated users that are in any of the trusted realms are mapped to the specified role. A list of realms to search is displayed. Users from the non-default realm are displayed as user@realm.

  • Everyone: Map everyone to the specified role. When you map everyone to a role, anyone can access the resources that are protected by this role and, essentially, there is no security.

  • None: Do not map anyone to the specified role.

  • If the secured realm cannot be reached, the left list is replaced with the text fields name, realm, and uid so that you can add the user directly.
  • We cannot map two subjects to the same role in this release of the product.

Parent topic: OSGi Applications administrative console panels

Related tasks:

Add an EBA asset to a composition unit
Add an EBA asset to a composition unit using wsadmin
Modify the configuration of an OSGi composition unit
Assign users and groups to roles

Related information:

Administrative console buttons
Administrative console preferences


Role

Lists the specific capabilities for a user. Role privileges give users and groups permission to run as specified.

For example, you might map the user Joe to the administrator role, which enables user Joe to complete all of the tasks associated with the administrator role.

The authorization policy is only enforced when global security is enabled.


Mapped users

Lists the users that are mapped to the specified role within this application.


Mapped groups

Lists the groups that are mapped to this specified role within this application.


Special subjects

Lists which special subjects are mapped to the security role when an application uses multiple realms.
Reference topic Feedback
Copyright IBM Corporation 2009, 2011. All Rights Reserved.
This information center is powered by Eclipse technology.

+

Search Tips   |   Advanced Search