
98
Novell Access Manager 3.1 SP2 J2EE Agent Guide
n
ov
do
cx (e
n)
16
Ap
ril 20
10
7
To test this configuration, send the following request from a browser:
http://<Application_Server_DNS_Name>:<port>/payroll
Replace
<Application_Server_DNS_Name>
with the DNS name or the IP address of your
application server.
Replace
<port>
with the port number you have configured the J2EE Agent to use.
8
Log in as a user who matches the condition to receive the Employee role and access the
My
Page
and the
Manager Page
.
9
Log out and log in as a user who matches the condition to receive the Manager role. Access the
My Page
and the
Manager Page
.
As a manager, you can add Employee Records so that when employees log in, their records are
displayed on
My Page
.
7.4 Using Access Manager Policies to Enforce
Authorization
The following procedure explains how to set up Access Manager policies that permit Managers to
access the manager pages in the sample payroll application, deny Employees access to the manager
pages, but permit Employees and Managers access to their own information pages. These policies
do not require any J2EE server configuration to correctly enforce the policies.
Section 7.4.1, “Creating an Employee Role and a Manager Role,” on page 98
Section 7.4.2, “Creating Authorization Policies,” on page 100
Section 7.4.3, “Assigning Policies to Protected Resources,” on page 105
Section 7.4.4, “Testing the Configuration,” on page 106
7.4.1 Creating an Employee Role and a Manager Role
If you have a particular application that requires more than one role, and it is the only application
using these roles, you can create one role policy that assigns users to the required roles. The
following steps explain how to create one role policy that assigns users to the Manager role and the
Employee role.
1
In the Administration Console, click
Devices
>
Policies
.
2
Click
New
, specify a name for the role policy, select
Identity Server: Roles
as the type, then
click
OK
.
3
For the first rule, click
New
, create a condition that matches your managers but not your
employees, activate the Manager role, then click
OK
.
The following rule uses the LDAP OU condition to determine whether the user is a manager. It
assumes that all managers are in the ou=managers,ou=payroll,o=novell container.
Содержание Access Manager 3.1 SP 2
Страница 4: ...4 Novell Access Manager 3 1 SP2 J2EE Agent Guide novdocx en 16 April 2010...
Страница 8: ...8 Novell Access Manager 3 1 SP2 J2EE Agent Guide novdocx en 16 April 2010...
Страница 44: ...44 Novell Access Manager 3 1 SP2 J2EE Agent Guide novdocx en 16 April 2010...
Страница 83: ...Preparing the Applications and the J2EE Servers 83 novdocx en 16 April 2010...
Страница 108: ...108 Novell Access Manager 3 1 SP2 J2EE Agent Guide novdocx en 16 April 2010...