Configure the WebLogic Adjudication provider

An Adjudication provider resolves authorization conflicts by weighing each Authorization provider's access decision and determining whether to permit access to the requested resource. If you only have one Authorization provider configured in the security realm and it is the WebLogic Authorization provider, then an ABSTAIN returned from the single Authorization provider is treated as a DENY. You can only have one Adjudication provider configured in a security realm, and you must have one Adjudication provider.

WebLogic Server offers the following types of Adjudication providers:

To configure the WebLogic Adjudication provider:

  1. If you have not already done so, in the Change Center of the Administration Console, click Lock & Edit (see Use the Change Center).
  2. In the left pane, select Security Realms and click the name of the realm you are configuring (for example, myrealm).
  3. Select Providers > Adjudication and click the name of the Adjudication provider.
  4. Optionally, select Configuration > Provider Specific and set Require Unanimous Permit. Do this if you want to require PERMIT to be returned from all Authorization providers in the realm in order to permit access to the requested resource.
  5. Click Save to save your changes.
  6. To replace the Adjudication provider, click the Replace button and configure a new Adjudication provider.
  7. To activate these changes, in the Change Center, click Activate Changes.
  8. Reboot WebLogic Server.

