Chapter 4. WebSphere Portal security
103
Document system changes
You should always document the system changes made, no matter whether it is a
configuration change, or deployment of applications, or a Fix Pack or interim fixes. The
change logs should be made available online, such that other people have access to them
later even after you have left the project.
The change journal or log can be as simple as the ones shown in Table 4-3.
Table 4-3 Configuration change log
You can add more information in the “What” column if you wish. Always make a backup copy
of the files you are going to change and save them to a separate location or a different hard
drive. The change log and these backup files should provide sufficient knowledge to recover
the system in case something goes wrong.
Before making any major changes, such as installing or upgrading the system or
configuration changes, you should always back up the system, including the database, LDAP,
and the file system. You should try to make these backups approximately at the same time, if
possible. See Appendix B, “Maintenance: Fix strategy, backup strategy, and migration
strategy” on page 207 for details.
Set up a security audit on the system
We highly recommend the AuditService be enabled all the time on all system environments.
For user and group management and portal access control purposes, we suggest the events
list shown in Table 4-4.
Table 4-4 audit log
Date
User ID
What
Apr 5, 2007
wpsadmin
Transferred database from Cloudscape to DB2.
Apr 20, 2007
janedoe
Installed Employee portlet application.
Aug 7, 2007
wpsadmin
Reconfigured security.
Sep 9, 2007
wpsadmin
Ran XMLaccess import to fix page order.
Do not to make multiple major changes at the same time. For example, do not configure
HTTP over SSL and TAM integration at the same time.
Event name
What is logged
audit.groupEvents
Group creation, modification, and deletion
audit.userEvents
User creation, modification, and deletion
audit.ownerEvents
Owner change of a resource
audit.resourceEvents
Resource creation, modification, and deletion
audit.userInGroupEvents
addition of a user to a group
Summary of Contents for BS029ML - WebSphere Portal Server
Page 2: ......
Page 14: ...xii IBM WebSphere Portal V6 Self Help Guide...
Page 22: ...8 IBM WebSphere Portal V6 Self Help Guide...
Page 68: ...54 IBM WebSphere Portal V6 Self Help Guide...
Page 98: ...84 IBM WebSphere Portal V6 Self Help Guide...
Page 150: ...136 IBM WebSphere Portal V6 Self Help Guide...
Page 240: ...226 IBM WebSphere Portal V6 Self Help Guide...
Page 241: ......