Sun Java System Access Manager 7.1 Technical Overview

Access Manager Information Tree

When installed in Realm Mode, Access Manager creates a special and proprietary branch in an LDAP data store for storing realm configurations, authentication properties, and authorization policies. Access Manager components and plug-ins access the data stored in the Access Manager information tree, and use it for various purposes including the following examples:

By default, the Access Manager information tree is created and maintained by Access Manager as a special branch in Sun Java System Directory Server, apart from any user data (identity repository). Figure 1–5 illustrates this default configuration.

Figure 1–5 Default Configuration for Access Manager Information Tree

Both the identity repository and the Access Manager
information tree can be installed on the same instance of Directory
Server.

But, the Access Manager information tree can also be created in a directory that is separate from the one hosting the Access Manager Identity Repository. Figure 1–6 illustrates this custom configuration.

Figure 1–6 Access Manager Information Tree Configured in Second Data Store

The identity repository can reside in one data
store, and the Access Manager information tree can reside in a different
data store.

The following figure compares two directory information trees: the first illustration represents a default hierarchical LDAP structure while the second represents the structure when the Access Manager information tree is integrated.

Figure 1–7 Directory Server With and Without an Access Manager Information Tree

This figure compares a default directory information
tree (DIT) with a DIT that includes the Access Manager information
tree.