Saturday Aug 23, 2008
Duffy, Lulu and Sub Realm Policy Administration in OpenSSO
Let's assume you have a top level realm named /opensso (because everybody has at one point). Under opensso create a sub realm called test. In the test sub realm, create a new user named usr1. Now create a new group, grp1, and assign read and write privileges for policy data to grp1 and assign usr1 to grp1.
test sub realm using the URL http://fdqn:port/opensso/UI/Login?realm=test and the name and password for usr1. The administration pages for the sub realm are displayed in order to manage its policy data. If you use the URL http://fdqn:port/opensso/UI/Login, the user's page is displayed in order to manage the user profile. This insures the following:
usr1will not have permission to manage policy data of the parent realm (openssoor any peer sub realms.usr1will have permissions to manage policy data of thetestsub realm and any realms created beneath it.
Posted at 07:52AM Aug 23, 2008 by Michael Teger in Sun | Comments[0]
Comments:
