Network Deployment (Distributed operating systems), v8.0 > Secure applications and their environment > Set up, enabling and migrating security > Enable security


Application security

Administrative security is enabled, by default. Application security is disabled, by default.

In previous releases of WAS, when a user enabled global security, both administrative and application security were enabled. Starting in WAS v6.1, global security is split into...

Application security is in effect only when administrative security is enabled.

An Application Server Enablement Tag, which is specific to WAS, is imported into the Interoperable Object Reference (IOR) to indicate if application security is disabled for the server where the object lives. This tag is server-specific and enables clients to know when application security is disabled at the target server of its request.

For web resources, when application security is enabled, security constraints on those resources in web.xml are enforced. When accessing a protected resource, a web client is prompted for authentication.

For enterprise bean resources, when application security is disabled, the client Common Secure Interoperability version 2 (CSIv2) code ignores the CSIv2 security tags for objects that are unknown system objects. When pure clients see that application security is disabled, these clients prompt for naming lookups, but do not prompt for enterprise bean operations.
Administrative security
Enable security


Related


Specify extent of protection wizard settings

+

Search Tips   |   Advanced Search