Sun Java System Access Manager 7.1 Administration Guide

Privileges

The delegation model in Access Manager is based on privileges (or entitlements) that have been assigned to the administrators. A privilege is an operation (or action) that can be performed on a resource; for example, a READ operation on Policy objects. The set of operations that are defined are READ, MODIFY and DELEGATE. The resources are objects on which the actions can be performed, and can be either a configuration object or an identity object.

Examples of configuration objects are Authentication Configuration, Policies, Data Stores, and so forth. Examples of identity objects are Users, Groups, Roles, and Agents. A set of privileges can be dynamically created and added to Access Manager dynamically, however during installation, a small set of privileges are added to get Access Manager to properly run. Once the privileges are loaded, the privileges can be assigned to roles and groups. Users belonging to these roles and groups would be the delegated administrators and would be able to perform the assigned operations. Basically, administrators are users who are members of roles and groups to which a set of one or more privileges are assigned.

Access Manager 7.1 allows you to configure permissions for the following administrator types:

Defining Privileges for Access Manager 7.1

A new installation instance of Access Manager 7.1 provides access permissions for policy administrators, realm administrators (or organization administrators in Legacy mode) and Log Administrators. To assign or modify privileges, click the name of the role or group you wish to edit. You can select from the following:

Read and write access to all log files

Defines both read and write access privileges to log administrators.

Write access to all log files

Defines only write access privileges to log administrators.

Read access to all log files

Defines only read access privileges to log administrators.

Read and write access only for policy properties

Defines read and write access privileges for policy administrators.

Read and write access to all realm and policy properties

Defines read and write access privileges for realm administrators.

Defining Privileges for an Access Manager 7.0 to 7.1 Upgrade

If you have upgraded Access Manager from version 7.0 to 7.1, the privilege configuration differs from that of a new Access Manager 7.1 installation, however privileges for policy administrators, realm administrators and log administrators are still supported. To assign or modify privileges, click the name of the role or group you wish to edit. You can select from the following:

Read only access to data stores

Defines read access privileges to datastores for policy administrators.

Read and write access to all log files

Defines both read and write access privileges for log administrators.

Write access to all log files

Defines only write access privileges for log administrators.

Read access to all log files

Defines only read access privileges for log administrators.

Read and write access only for policy properties

Defines read and write access privileges for policy administrators.

Read and write access to all realm and policy properties

Defines read and write access privileges for realm administrators.

Read only access to all properties and services

Defines read access privileges to all properties and services for policy administrators.

Access Manager does not support the following definitions used either separately or together:

These privilege definitions must be used with the “Read and write access only for policy properties” definition to define delegation control for policy administrators.