Sun Java logo     ĸġÓ÷      Æøòç      ×ÄÅ¿      ĶġÓ÷     

Sun logo
Sun Java[TM] System Identity Manager 7.1 ê§Ü¡ 

ÜÉ 12 Ýý
î¨ÕøØ´òç

ÆÛÝýë©Íü Sun Java System Identity Manager î¨ÕøË·ÜÓÇñÈôØ´òçËçǵ¡¤æñعÜÚöþÇñĶ¡¨


äÍÎÓ

Identity Manager î¨ÕøÎûÆøÎûÑÒØ´òçï¡ÇãÄïëûÕëâæè×ÔáËè Identity Manager ÎìǵÙÚÈçħÄïëûÉ¢äÆ¡¤

î¨ÕøËçǵÆñÄ¡Ô¶ÍÐÇéÔ¶àõÉ©á£È¢Ý¨Ü¡¡¤ËíçßÝá¢Identity Manager ËðÆîóÃÇôÕ»àõÉ©á£È¢Ùòî¨ÕøËçǵشòçÇãóÃÇôÕ»Ä㡤Ԭɷî¨ÕøåúÜÚ¡¢ñäòÙÆ«ÅèÄøÝÂê§Ü¡ÔÞòÙ̽î¨ÕøËçǵÄÍâõâÐÈçØ´ò硤ÚÀÆ«Ò³ÊäÔ¶àõÉ©á£È¢ÑÀÌùÄ¡Ô¶ÍÐÇéÔ¶Þ²ÏÏÄØÚöÆîÎûî¨ÕøåúÜÚ¡¤


Þ¬â¡

ÇñëæÈ´ùÃéñáþůê§Ü¡ËðÆîϯç°Ý½Îûæñع¡¢îùÙ¶ïåÜÉ 11 Ýý¡ÖËÎǹøüɱî¨Õø¡×¡¤



Identity Manager î¨ÕøÄïëûÄùÕ©¡©

ÄËÇéí°çßÝÃî¨ÕøÝçÆñÄùÝå Identity Manager Ä÷ǵÙÚÈ硤ÈþÑÒ¡¢È´ËèÄõÓòÄøÝÂÚ·ÄÖÉ¢Ñüá£ÍÐÚ· Java á£È¢î£Ü¨ÆíËçǵ¡¤

çßÝà Identity Manager î¨ÕøÅÉÎÎÅäÓÑÆñƾԶÅäÓÑÙ´ÙÑÙÚÈ硨


ÐúÇ¡Ëçǵ

ö£àÓ Identity Manager ƫݨܡÄùÝåî¨Õø¡¢ÈþÑÒÇãÑÜËèÚÅÎÓĶ¡¢ÚÀÆ«×äʨ۬ڷÈÜÓÔÄÖÉ¢Ñüá£Ø´òçî¨ÕøËçǵ¡¤

Ú·ÄÖÉ¢Ñüá£î¨Õø

ËðÆî com.waveset.session.WorkflowServices óÜÆîá£È¢Æ«Ú·Ç¶ÈôÄÖÉ¢Ñüá£á£Ê©ÄãܨÆíî¨ÕøËçǵ¡¤ÏР12-1 ë©ÍüħïËÆîÍõȺóÜÆîá£È¢ÎûÅ¿í°¡¤

ÏР12-1 ïËÆîÍõ com.waveset.session.WorkflowServices ÎûÅ¿í°

Å¿í°

ùËÐÎ

ë©Íü

op

ÇóÈë

WorkflowServices ÎûÉ¢äÆ¡¤ÆÒâüÝÃÌùÒ³î¨Õø¡¤

type

ÇóÈë

ÓÑî¨ÕøÎûÎìǵùËÐÎÇØꢡ¤

action

ÇóÈë

ÄØÙÚÈçÎûٯɢÇØꢡ¤

status

ÇóÈë

ÑÀÌùٯɢÎûÎíèèÇØꢡ¤

name

ÇóÈë

Ì¿ÑÀÌùٯɢìàûÀÎûÎìǵÇØꢡ¤

resource

ÇóÈë

(òÙðåÍÌ) ÓÑüÈÊÕÎìǵÍÔÇãÄææñäãÎûÇØꢡ¤

accountId

ÇóÈë

(òÙðåÍÌ) ÓÑÔºÊÑÎûÚ¨æÀ ID¡¤ ̧óÜÒ³ÆÛñ¢æñäãÚ¨æÀÇØꢡ¤

error

ÇóÈë

(òÙðåÍÌ) àõÆíǶÈôÆÂÚõÕë¡¢ÝçäÄüÏÆüÄØÆÛÄÈŧÎûòãë¨ÇóÈ롤

reason

ÇóÈë

(òÙðåÍÌ) ReasonDenied ÎìǵÎûÇØꢡ¢äÄè×ÑÐÈÝë©ÍüÄ¡×ïÆÂÚõÔÏÇÞÎûÙÏëãŧعÕÉ¡¤

attributes

è×ÑÐ

(òÙðåÍÌ) ÄØìÁÅûÍÐÄØÔºÊÑÄæúèÍÌÇØê¢ÌÏúèÍÌÔ«Îûè×ÑС¤

parameters

è×ÑÐ

(òÙðåÍÌ) Þ²Çéè×ÑÐÄìÔ¶êØÄ¡Ô¶ËçǵÒÞùÃÎûÏáÅûÇØê¢ÍÐÔ«¡¤

organizations

ÛÒÞÌ

ÙòÍóåôȺËçǵÎûÜÚöþÇØê¢ÍÐ ID ÛÒÞÌ¡¤Ì§ÆîÍõÝÃÌùî¨ÕøØ´òçÎûÜÚöþî¯ÞØ¡¤ÇñΪÄâÇôÇ㡢Ьݨܡá£È¢Ùòè©æÜÕüðãùËÐÎÌÏÇØê¢æØεÜÚöþ¡¤ÇñΪàÒÎÎæØεÜÚöþ¡¢Ð¬äÄÙòËçǵÍóåôÇãÞ¡ìÒ (ÜÚöþâêìÒÎûÞ²ØíìÒ×È)¡¤

originalAttributes

è×ÑÐ

(òÙðåÍÌ) ÷®úèÍÌÔ«Îûè×ÑС¤ÇØê¢óÜêØúèÍÌÅ¿í°ÄãÇÄÅøÎûÇØê¢ÒÞÜÊ¡¤Ô«ÙòÒ³ÚÀʨ۬óÃÇôÇãî¨ÕøØ´òçÄãÄæǶÈôǿЩÎûÔ«¡¤

îùÙ¶ïåÏР12-18¡¢Åè̽ڵçßÝÃÎìǵ¡£Ù¯É¢ÌÏÎíèèÇØê¢ÎûÛÒÞÌ¡¤

î¯Ëó

á£È¢î£î¯Ëó 12-1 ë©ÍüħġԶöüÞÌÄÖÉ¢Ñüá£É¢äÆ¡¤Èºî¯ËóüÏÆüħËçǵܨÆíç´á£¡¢æÚËçǵÙòØ´òçÆñ ResourceAdministrator ÙÚÈçÄæÇØÒ³ ADSIResource1 ÎûæñäãÉ´ØæÉ¢äÆ¡¨

á£È¢î£î¯Ëó 12-1 öüÞÌÄÖÉ¢Ñüá£É¢äÆ

 

<Activity name='createEvent'>

   <Action class='com.waveset.session.WorkflowServices'>

   <Argument name='op' value='audit'/>

   <Argument name='type' value='Resource'/>

   <Argument name='action' value='Delete'/>

   <Argument name='status' value='Success'/>

   <Argument name='subject' value='ResourceAdministrator'/>

   <Argument name='name' value='ADSIResource1'/>

   </Action>

   <Transition to='end'/>

</Activity>

 

á£È¢î£î¯Ëó 12-2 üÏÆüħÇñÈôÙòÖÖÌùúèÍÌìÁÅûÈÝÑÜÔ¶ÄÖÉ¢Ñüᣡ¢æÚÄÖÉ¢Ñüá£Æ«ØÑ÷ÇÊäÔ¶ËðÆîϯÇãÕøÔÆá£Ê©ÄãÔïÆîÈÝö¨ÜÎÍÌìÒ×ÈÎûüÈÊÕ¡¤Ý×Ú¦¡¢ÈºìÁÅûѺäùîùÊåËðÆîϯòÓÄ«Îû ManualAction âÐÈ硤

ACTUAL_APPROVER ÑÒÕüðãèÒëãÙÚÈçÕøÔÆÎûÄ©ÔÞ¡¢ÇãÏÐÞÌÌÏÄÖÉ¢Ñüᣠ(ÇñΪڷÕøÔÆÏÐâÐÈçÕøÔÆ) ÄãÝÃÌùÎû¡¤APPROVER Æ«øüɱÙò̧ÑÀÌùá¿ï¡¡¤

á£È¢î£î¯Ëó 12-2 ÆîÍõÇãÕøÔÆá£Ê©ÄãØÑ÷ÇüÈÊÕÎûÄØìÁÅûúèÍÌ

<Action name='Audit the Approval'    application='com.waveset.session.WorkflowServices'>

     <Argument name='op' value='audit'/>

     <Argument name='type' value='User'/>

     <Argument name='name' value='$(CUSTOM_DESCRIPTION)'/>

     <Argument name='action' value='approve'/>

     <Argument name='accountId' value='$(accountId)'/>

     <Argument name='status' value='success'/>

     <Argument name='resource' value='$(RESOURCE_IF_APPLICABLE)'/>

     <Argument name='loginApplication' value='$(loginApplication)'/>

     <Argument name='attributes'>

       <map>

          <s>fullname</s><ref>user.accounts[Lighthouse].fullname</ref>

          <s>jobTitle</s><ref>user.accounts[Lighthouse].jobTitle</ref>

          <s>location</s><ref>user.accounts[Lighthouse].location</ref>

          <s>team</s><ref>user.waveset.organization</ref>

          <s>agency</s><ref>user.accounts[Lighthouse].agency</ref>

      </map>

    </Argument>

    <Argument name='originalAttributes'>

      <map>

<s>fullname</s>

        <s>User's previous fullname</s>

        <s>jobTitle</s>

        <s>User's previous job title</s>

        <s>location</s>

        <s>User's previous location</s>

        <s>team</s>

        <s>User's previous team</s>

        <s>agency</s>

        <s>User's previous agency</s>      </map>

    </Argument>

    <Argument name='attributes'>

      <map>

         <s>firstname</s>

         <s>Joe</s>

         <s>lastname</s>

         <s>New</s>

      </map>

    </Argument>

    <Argument name='subject'>

       <or>

          <ref>ACTUAL_APPROVER</ref>

          <ref>APPROVER</ref>

      </or>

    </Argument>

    <Argument name='approver' value='$(APPROVER)'/>

</Action>


î¨ÕøØÙåô

î¨ÕøØÙåôÆñÄ¡Ô¶ÍÐÇéÔ¶àõÉ©á£È¢Åèůí°Ô¶çßÇ¿ÌùåøÎûåúÜÚÜÚÈ©¡¤

î¨ÕøåúÜÚÆ«ÕüðãÎìǵùËÐΡ£Ù¯É¢ÌÏٯɢá¸ÎªÌùåøÍÔÈ´î¨ÕøËçǵÎûÄÍâõ¡¤ÊäÔ¶àõÉ©á£È¢Ýç̦ȴġԶÍÐÇéÔ¶ÑÀÌùÎûî¨ÕøåúÜÚ¡¤ËíçßÝá¢ÙòóÃÇôÕ»àõÉ©á£È¢ÑÀÌùá¿ÍÔÈ´î¨ÕøåúÜÚ¡¤

î¨ÕøàõÉ©á£È¢Æ«Ùòî¨ÕøËçǵã®ØÊÈÝÖÖÌùÎûî¨ÕøÆøíº¡¤çßÝÃÎûóÃÇôÕ»àõÉ©á£È¢Æ«Ùòî¨ÕøØ´òçìÑÄ«óÃÇôÕ»¡¤ÊäÔ¶î¨ÕøàõÉ©á£È¢Éáƫ̦ȴèÒÉ¢ÖÖÌùòÙâú¡¤Æ«ÅèÒ³î¨ÕøàõÉ©á£È¢ÑÀÌùÅÆÇó֪Ȣŧá£È¢¡¨ÅÆÇó֪Ȣŧá£È¢Æ«ßÈËòî¨ÕøËçǵÎûÅÆÇóë©Íü¡¤

î¨ÕøØÙåô (#ID#Configuration:AuditConfiguration) ÎìǵÇã sample/auditconfig.xml óòÕùÄãÌùåø¡¤ÈºØÙåôÎìǵ̦ȴġԶͷÈú¡¢æÚÍ·ÈúÑÒÄ¡Ô¶Ý×ÆîÎìǵ¡¤Ì§ÈíÍõÞ¡ìÒ¡¢Ì¦È´ÅèĶúèÍÌ¡¨

filterConfiguration

filterConfiguration úèÍÌÆ«ÇÄÅøËçǵåúÜÚ¡¢ÝÕËèåúÜÚÆîÍõËðÄ¡Ô¶ÍÐÇéÔ¶ËçǵÝ×ç´ËçǵñäòÙð¡¤filterConfiguration úèÍÌÄãÇÄÅøÎûÊäÔ¶åúÜÚÉáÅýÉÖÏР12-2 ÄãÇÄÅøÎûúèÍÌ¡¤

ÏР12-2 filterConfiguration úèÍÌ

úèÍÌ

ùËÐÎ

ë©Íü

groupName

ÇóÈë

ËçǵåúÜÚÇØê¢

displayName

ÇóÈë

ÏÐÆüåúÜÚÇØê¢ÎûعÕÉÆøòçùÃõïÇó

enabled

ÇóÈë

ÑÀÆüÄØÚöÆîõäÑÒÄØØôÆîðìÔ¶åúÜÚÎûÆÌίé¡íº¡¤ÈºúèÍÌÑÒñäòÙÎìǵÎûÞ²ËïúèÍÌ¡¤

enabledEvents

List

ë©ÍüåúÜÚÚöÆîÔáËèËçǵÎûÝ×ÆîÎìǵÛÒÞÌ¡¤ÆÒâüÇÄÅøËçǵÅèÚöÆî̧شò硤ÇÄÅøÎûÊäÔ¶ÎìǵÉáÆÒâü̦ȴÅèĶúèÍÌ¡¨

  • objectType (ÇóÈë) - ÌÔÇØÎìǵùËÐΡ¤
  • actions (ÛÒÞÌ) - Ä¡Ô¶ÍÐÇéԶٯɢÎûÛÒÞÌ¡¤
  • results (ÛÒÞÌ) - Ä¡Ô¶ÍÐÇéÔ¶á¸ÎªÎûÛÒÞÌ¡¤

á£È¢î£î¯Ëó 12-3 ë©ÍüħçßÝÃæñäãê§Ü¡åúÜÚ¡¤

á£È¢î£î¯Ëó 12-3 çßÝÃæñäãê§Ü¡åúÜÚ

<Object name='Resource Management'>

  <Attribute name='enabled' value='true'/>

  <Attribute name='displayName'

             value='UI_RESOURCE_MGMT_GROUP_DISPLAYNAME'/>

  <Attribute name='enabledEvents'>

    <List>

      <Object>

        <Attribute name='objectType' value='Resource'/>

        <Attribute name='actions' value='ALL'/>

        <Attribute name='results' value='ALL'/>

      </Object>

      <Object>

        <Attribute name='objectType' value='ResourceObject'/>

        <Attribute name='actions' value='ALL'/>

        <Attribute name='results' value='ALL'/>

      </Object>

    </List>

  </Attribute>

</Object>

Identity Manager ßÈËòħÅèĶçßÝÃËçǵåúÜÚ¡¨

ÚÀÆ«ÅèÚ· Identity Manager ê§Ü¡ÄõÓòÎû [Audit Events] Ó÷ÓòØÙåôÊäÔ¶åúÜÚ (configure/auditeventconfig.jsp)¡¤ÈºÓ÷ÓòÆ«üéÚÀØÙåôÊäÔ¶åúÜÚÎûÈ©ÅüÍÐÆÂÚõËçǵ¡¤ÈºÄõÓòÄâÅÅßÎìÁÅûÍÐÔºÊÑåúÜÚÎû enabledEvent¡¢ÈþÑÒÚÀÆ«ÅèËðÆî Identity Manager ØæòãÓ÷ÓòÙÚÈçÝÕËèÉ¢äÆ¡¤

çßÝÃËçǵåúÜÚů̧ÚöÆîÎûËçǵÇãÅèĶÇÖåçÄãë©Íü¡¤

Ú¨æÀê§Ü¡

ËíçßÝÃÚöÆîȺåúÜÚ¡¤

ÏР12-3 çßÝÃÚ¨æÀê§Ü¡ËçǵåúÜÚ

ùËÐÎ

ٯɢ

æñäãÚ¨æÀ

ÐúÇ¡¡£ÊÕ仡£É´Øæ¡£ÚöÆî¡£ØôÆî¡£ÍÜạ£ÕøÔÆ¡£Óìä»ÌÔÇØ

Identity Manager Ú¨æÀ

ÐúÇ¡¡£ÊÕ仡£É´Øæ¡£ÚöÆî¡£ØôÆî¡£Óìä»ÌÔÇØ

ò×ߧÍÌê§Ü¡

ËíçßÝÃÚöÆîȺåúÜÚ¡¤

ÏР12-4 çßÝÃݽî¯ò×ߧê§Ü¡åúÜÚËçǵ

ùËÐÎ

ٯɢ

AuditPolicy

ÍÔȴٯɢ

ComplianceViolation

ÍÔȴٯɢ

ÔºÆßÄÖÉ¢Ñüá£

ÍÔȴٯɢ

ØÙåôê§Ü¡

ËíçßÝÃÚöÆîȺåúÜÚ¡¤

ÏР12-5 çßÝÃØÙåôê§Ü¡ËçǵåúÜÚ

ùËÐÎ

ٯɢ

ØÙåô

ÍÔȴٯɢ

UserForm

ÍÔȴٯɢ

Rule

ÍÔȴٯɢ

EmailTemplate

ÍÔȴٯɢ

LoginConfig

ÍÔȴٯɢ

á¬Ü©

ÍÔȴٯɢ

XMLData

ã¾Ä«

Ø´òç

ÍÔȴٯɢ

Identity Manager àôÄ«/àôÅø

ËíçßÝÃÚöÆîȺåúÜÚ¡¤

ÏР12-6 çßÝà Identity Manager àôÄ«/àôÅøËçǵåúÜÚ

ùËÐÎ

ٯɢ

ËðÆîϯ

àôÄ«¡£àôÅø¡£ðÕøýç´ßæ

ê§Ü¡ÔÞ

àôÄ«¡£àôÅø¡£ðÕøýç´ßæ

Ùïî£ê§Ü¡

ËíçßÝÃÚöÆîȺåúÜÚ¡¤

ÏР12-7 çßÝÃÙïî£ê§Ü¡ËçǵåúÜÚÌÏËçǵ

ùËÐÎ

ٯɢ

æñäãÚ¨æÀ

üÈÊÕ/ÓìÝÃÙïî£

æñäãê§Ü¡

ËíçßÝÃÚöÆîȺåúÜÚ¡¤

ÏР12-8 çßÝÃæñäãê§Ü¡ËçǵåúÜÚÌÏËçǵ

ùËÐÎ

ٯɢ

æñäã

ÍÔȴٯɢ

æñäãÎìǵ

ÍÔȴٯɢ

ResourceForm

ÍÔȴٯɢ

ResourceAction

ÍÔȴٯɢ

AttrParse

ÍÔȴٯɢ

ËÅÈãê§Ü¡

ËíçßÝÃØôÆîȺåúÜÚ¡¤

ÏР12-9 çßÝÃËÅÈãê§Ü¡ËçǵåúÜÚÌÏËçǵ

ùËÐÎ

ٯɢ

ËÅÈã

ÍÔȴٯɢ

ÇøÇÀê§Ü¡

ËíçßÝÃÚöÆîȺåúÜÚ¡¤

ÏР12-10 çßÝÃÇøÇÀê§Ü¡ËçǵåúÜÚÌÏËçǵ

ùËÐÎ

ٯɢ

ObjectGroup

ÍÔȴٯɢ

ê§Ü¡ÔÞåúÜÚ

ÍÔȴٯɢ

ê§Ü¡ÔÞ

ÍÔȴٯɢ

EncryptionKey

ÍÔȴٯɢ

É¢äÆê§Ü¡

ËíçßÝÃØôÆîȺåúÜÚ¡¤

ÏР12-11 É¢äÆê§Ü¡ËçǵåúÜÚÌÏËçǵ

ùËÐÎ

ٯɢ

TaskInstance

ÍÔȴٯɢ

TaskDefinition

ÍÔȴٯɢ

TaskSchedule

ÍÔȴٯɢ

TaskResult

ÍÔȴٯɢ

ProvisioningTask

ÍÔȴٯɢ

Identity Manager ÄæÆÀÎûüÈÊÕ

ËíçßÝÃØôÆîȺåúÜÚ¡¤

ÏР12-12 Identity Manager ÄæÆÀÎûüÈÊÕËçǵåúÜÚÌÏËçǵ

ùËÐÎ

ٯɢ

ResourceAccount

ÆÛñ¢üÈÊÕ

Service Provider Edition

ËíçßÝÃÚöÆîȺåúÜÚ¡¤

ÏР12-13 Service Provider Edition ËçǵåúÜÚÌÏËçǵ

ùËÐÎ

ٯɢ

IDMXUser

ÐúÇ¡¡£ÔºÊÑ¡£É´Øæ¡£ËðÆîϯÇØê¢Çßߦ¡£ææÙÂÇßóÜ¡£ÊÕä»ë¥øýá°Õù¡£É¢äÆЩÌÏÉ¢äÆÑ¥è·ë©ÅÆÇó¡£

extendedTypes

ÚÀìÁÅûÈÝ com.waveset.object.Type ùËɱÎûÊäê¡ä»ùËÐÎÉáÆ«î¨Õø¡¤ÆÒâüÒ³ä»ùËÐÎÑÀÌùÙÄÄ¡Îû÷äÇóÄ÷æñÕèÕ»ùÃõïÇó¡¢Ì§ÙòóÃÇôÇãæñÕèÕ»Ä㡤ÍÔÈ´ä»ùËÐÎÉáÙòìÁÅûÈÝÄâÇÑÎûî¨ÕøÞÞÉËÄõÓò¡¤ÆÒâüÙòÊäÔ¶ÄâåîñäòÙÞóØ´òçÈÝæñÕèÕ»Îûä»ùËÐÎìÁÅûÈÝî¨ÕøËçǵåúÜÚ enabledEvents úèÍÌÄã (Çñ enabledEvents úèÍÌÎûë©Íü)¡¤

ÇãÑÜËèÚÅÎÓĶ¡¢ÚÀÆ«×äʨ۬î¨ÕøÊôÈ´ÒÞùà com.waveset.objectType ÎûÎìǵ¡¢ÍÐϯʨ۬ÊÕæÛÜØÇâÏÐÆüܢȴùËÐΡ¤

ËóÇñ¡¢WSUser ÎìǵäÄÙòËðÆîϯÎûÍÔÈ´Ú¨æÀæñعóÃÇôÇãóÃÇôÕ»Ä㡤î¨Õøá£Ê©Ùò WSUser Îìǵš޴ҳ̥ԶÄâÇÑÎûî¨ÕøùËÐÎ (æñäãÚ¨æÀÌÏ Identity Manager Ú¨æÀ)¡¢ÈÔÄâÑÒÙòÊäÔ¶ËçǵíºØ´Ò³ USER ùËÐΡ¤ÅèȺÅÉÎÎÅ¡Þ´ÎìǵƫüéÚÀÊÕë¼÷úÇâÇãî¨ÕøØ´òçÄãÞòÊÆÖÖÌùÚ¨æÀæñع¡¤

Ýàç´ìÁÅûÈÝ extendedObjects úèÍÌËôìÁÅûÍ·ÈúÈ¢î¨ÕøùËÐΡ¤ÊäԶͷÈúÈ¢ÎìǵÉáÆÒâü̦ȴĶÏÐÄãÇÄÅøÎûúèÍÌ¡¨

ÏР12-14 Í·ÈúÈ¢ÎìǵúèÍÌ

Å¿í°

ùËÐÎ

ë©Íü

name

ÇóÈë

ùËÐÎÇØꢡ¢ÇãÐúé¬î¨ÕøËçǵÕëÌÏñäòÙËçǵßæâæËðÆ

displayName

ÇóÈë

ÏÐÆüùËÐÎÇØê¢ÎûعÕÉÆøòçùÃõïÇó¡¤

logDbKey

ÇóÈë

ÇãØ´òçÏÐÄãóÃÇôȺÎìǵÕëÓÑËðÆîÎû÷äÇóÄ÷æñÕèÕ»ùÃõïÇó¡¤îùÙ¶ïåØ´òçæñÕèÕ»ùÃõïÇóÅè̽ڵÏñÖçÔ«¡¤

supportedActions

List

ÎìǵùËÐÎÅÅßÎÎûٯɢ¡¤Ú·ËðÆîϯÄõÓòÐúÇ¡î¨ÕøÑçææÕëÙòËðÆîȺúèÍÌ¡¤ÇñΪæÚԫҳϨԫ¡¢Ð¬ÍÔȴٯɢÉáäÄüÏÆüÒ³ÓÑØÜè×ȺÎìǵùËÐÎÑçææÎûÆ«×äÔ«¡¤

mapsToType

ÇóÈë

(òÙðåÍÌ) è×ÑÐÈÝȺùËÐÎÎû com.waveset.object.Type ÇØê¢ (ÇñΪȴ)¡¤è©æÜæØεÎìǵÜÚöþÈ©ÔÞËÎǹ (ÇñΪÌþÆÜÇãËçǵĸÑÀÌù) ÕëäÄËðÆîȺúèÍÌ¡¤

organizationalMembership

List

(òÙðåÍÌ) óÜÍóåôȺùËÐÎËçǵ (ÇñΪÆÆÔ¯ÌþÆÜ̦ȴÑÀÌùÎûÜÚöþÈ©ÔÞËÎǹ) ÄæÜÚöþ ID ÎûçßÝÃÛÒÞÌ¡¤

ÍÔÈ´ÆîÅÂÖÖÌùùÃõïÇóÉáóÜÅè # ÜÊæÀâä󤡢ÅèËßÅÏìÁÅûä»ÎûÄùÝåùÃõïÇóÑ¥ÅøÜ¢ÓìîïÎûùÃõïÇó¡¤

á£È¢î£î¯Ëó 12-4 ë©ÍüħͷÈúÈ¢ùËÐÎ Identity Manager Ú¨æÀ¡¤

á£È¢î£î¯Ëó 12-4 Í·ÈúÈ¢ùËÐÎ Identity Manager Ú¨æÀ

<Object name='LighthouseAccount'>

   <Attribute name='displayName' value='LG_LIGHTHOUSE_ACCOUNT'/>

   <Attribute name='logDbKey' value='LA'/>

   <Attribute name='mapsToType' value='User'/>

   <Attribute name='supportedActions'>

      <List>

         <String>password</String>

         <String>Enable</String> 

         <String>Create</String>

         <String>Modify</String>

         <String>Delete</String>

         <String>Rename</String>

      </List>

   </Attribute>

</Object>

extendedActions

î¨ÕøٯɢÝ×Ú¦è×ÑÐÈÝ com.waveset.security.Right Îìǵ¡¤ìÁÅûä»Îû Right ÎìǵÕë¡¢ÚÀÆÒâüÑÀÌùÙÄÄ¡Îû÷äÇóÄ÷ logDbKey¡¢Ì§ÙòóÃÇôÇãæñÕèÕ»Ä㡤ÚÀÆ«×äç²Ì¯ÝÕê¡ÚÅÎÓ¡¢É»àÒûâêØÆÒâüî¨ÕøÄæÖÖÌùٯɢè×óÜ¡¤ÚÀÆ«ÅèÝàç´ÙòٯɢìÁÅûÈÝ extendedActions úèÍÌÄãÎûÎìǵÛÒÞÌÄãËôÍ·Èúٯɢ¡¤

ÊäÔ¶ extendedActions ÎìǵÉáÆÒâüÅýÉÖÏР12-15 ÄãÇÄÅøÎûúèÍÌ¡¤

ÏР12-15 extendedAction úèÍÌ

úèÍÌ

ùËÐÎ

ë©Íü

name

ÇóÈë

ٯɢÇØꢡ¢ÇãÐúé¬î¨ÕøËçǵÕëÌÏñäòÙËçǵßæâæËðÆ

displayName

ÇóÈë

ÏÐÆüٯɢÇØê¢ÎûعÕÉÆøòçùÃõïÇó¡¤

logDbKey

ÇóÈë

ÇãØ´òçÏÐÄãóÃÇôȺٯɢÕëÓÑËðÆîÎû÷äÇóÄ÷æñÕèÕ»ùÃõïÇó¡¤

îùÙ¶ïåØ´òçæñÕèÕ»ùÃõïÇóÅè̽ڵÏñÖçÔ«¡¤

ÍÔÈ´ÆîÅÂÖÖÌùùÃõïÇóÉáóÜÅè # ÜÊæÀâä󤡢ÅèËßÅÏìÁÅûä»ÎûÄùÝåùÃõïÇóÑ¥ÅøÜ¢ÓìîïÎûùÃõïÇó¡¤

á£È¢î£î¯Ëó 12-5 ë©ÍüħÇñÈôìÁÅûàôÅøٯɢ¡¤

á£È¢î£î¯Ëó 12-5 ìÁÅûàôÅøٯɢ

<Object name='Logout'>

  <Attribute name='displayName' value='LG_LOGOUT'/>

  <Attribute name='logDbKey' value='LO'/>

</Object>

extendedResults

ØæħͷÈúî¨ÕøùËÐÎÌÏٯɢÄæÆÀ¡¢ÚÀõäÆ«ÅèìÁÅûá¸Îª¡¤ËíçßÝá¢È´Ì¥ê¡á¸Îª¡¨È©ÅüÌÏÆÂÚõ¡¤ÚÀÆ«ÅèÝàç´Ùòá¸ÎªìÁÅûÈÝ extendedResults úèÍÌÄãÎûÎìǵÛÒÞÌÄãËôÍ·Èúá¸Îª¡¤

ÊäÔ¶ extendedResults ÎìǵÉáÆÒâüÅýÉÖÏР12-16 Äãë©ÍüÎûúèÍÌ¡¤

ÏР12-16 extendedResults úèÍÌ

úèÍÌ

ùËÐÎ

ë©Íü

name

ÇóÈë

á¸ÎªÇØꢡ¢ÇãÝÃÌùî¨ÕøËçǵÎûÎíèèÕëÌÏñäòÙËçǵßæâæËðÆ

displayName

ÇóÈë

ÏÐÆüá¸ÎªÇØê¢ÎûعÕÉÆøòçùÃõïÇó¡¤

logDbKey

ÇóÈë

ÇãØ´òçÏÐÄãóÃÇôȺá¸ÎªÕëÓÑËðÆîÎûÞÌÇóÄ÷æñÕèÕ»ùÃõïÇó¡¤îùÙ¶ïåíº÷îÒ³æñÕèÕ»ùÃõïÇóÎûÄÑåç¡¢Åè̽ڵÏñÖçÔ«¡¤

ÍÔÈ´ÆîÅÂÖÖÌùùÃõïÇóÉáóÜËðÆî 0 ̯ 9 ÄæâæÎûí°Çó¡¢ÅèËßÅÏìÁÅûä»ÎûÄùÝåùÃõïÇóÑ¥ÅøÜ¢ÓìîïÎûùÃõïÇó¡¤

àõÉ©á£È¢

àõÉ©á£È¢ÛÒÞÌÄãÎûÊäÔ¶âúÆøÉáÒ³Ý×ÆîÎìǵ¡¤ÊäÔ¶àõÉ©á£È¢Éá̦ȴÅèĶúèÍÌ¡¨

ÏР12-17 àõÉ©á£È¢úèÍÌ

úèÍÌ

ùËÐÎ

ë©Íü

class

ÇóÈë

àõÉ©á£È¢ùËɱÎûÇØꢡ¤

displayName

ÇóÈë

ÏÐÆüàõÉ©á£È¢ÇØê¢ÎûعÕÉÆøòçùÃõïÇó¡¤

description

ÇóÈë

è×àõÉ©á£È¢Îûë©Íü¡¤

filters

List

ÑÀÌùá¿ÈºàõÉ©á£È¢Îûî¨ÕøåúÜÚÛÒÞÌ¡¤

formatter

ÇóÈë

ÅÆÇó֪Ȣŧá£È¢ÎûÇØê¢ (ÇñΪȴ)¡¤

options

List

àõÉ©á£È¢òÙâúÛÒÞÌ¡¤ÝÕËèòÙâúÑÒàõÉ©á£È¢ÖÖÌùÎû¡§ÛÒÞÌÄãÎûÊäÔ¶âúÆøÉáÑÒ PublisherOption Îûè×ÑÐÏÐÆü¡¤îùÙ¶ïå sample/auditconfig.xml Åè̽ڵî¯Ëó¡¤


æñÕèÕ»í¼È¢

Identity Manager æñÕèÕ»ÄãÈ´Ì¥Ô¶ÆîÍõóÃÇôî¨ÕøæñÕèÎûÏÐÖª¡¨

waveset.log

ÆÛÄÑåçÇÄÅøħ waveset.log ÏÐÄãÎûÇÖúñÇØê¢ÌÏæñÕèùËÐΡ¤æñÕèùËÐÎÑÒÕüðã Oracle æñÕèÕ»Ìùåø̽ڵÎû¡¢ËääÄÇÞæñÕèÕ»ÎûÄâÇÑÈÔá¡È´ÄâÇÑ¡¤ÇñëæÍÔÈ´Ì¿ÅÅßÎæñÕèÕ»ÎûæñÕèí¼È¢Ô«ÛÒÞÌ¡¢îùÙ¶ïåÏáòç C¡Öî¨ÕøØ´òçæñÕèÕ»í¼È¢¡×¡¤

Ò³åçÒÜϨâ桢ġËèúñÔ«ÇãæñÕèÕ»ÄãóÃÇôÒ³ùÃõïÇó¡¤ÇñëæùÃõïÇóÌùåø¡¢îùÙ¶ïåíº÷îҳشòçæñÕèÕ»ùÃõïÇóÎûÄÑåç

waveset.logattr

waveset.logattr ÏÐÆîÍõóÃÇôÊäÔ¶ËçǵÎûÜÚöþÈ©ÔÞËÎǹ ID¡¢ÝÕÆ«ÅèËíÜÚöþÝÃÌùî¨ÕøØ´òçî¯ÞØ¡¤


Ø´òçæñÕèÕ»ùÃõïÇó

ÎìǵùËÐΡ£Ù¯É¢¡£Ù¯É¢ÎíèèÌÏÔÏÇÞúñÇãæñÕèÕ»ÄãóÃÇôÒ³ùÃõïÇó¡¢ÅèåçÒÜϨâ桤

ÎìǵùËÐΡ£Ù¯É¢ÌÏá¸Îª

ÏР12-18 ë©ÍüħÇãæñÕèÕ»ÄãóÃÇôÒ³ùÃõïÇóÎûÎìǵùËÐΡ£Ù¯É¢ÌÏá¸Îª¡¨

ÏР12-18 óÃÇôÒ³ùÃõïÇóÎûÎìǵùËÐΡ£Ù¯É¢ÌÏá¸Îª

ÎìǵùËÐÎÇØê¢

æñÕèÕ»ùÃôúÇó

ٯɢÇØê¢

æñÕèÕ»ùÃôúÇó

á¸ÎªÇØê¢

æñÕèÕ»ùÃôúÇó

Ú¨æÀ

AN

ÕøÔÆ

AP

È©Åü

S

ê§Ü¡ÔÞ

AD

Ü©ç´üÓøý

BV

ÆÂÚõ

F

ê§Ü¡ÔÞåúÜÚ

AG

ּ̽îþæØ

CR

 

 

úèÍÌÌùåø

AF

challengeResponse

CD

 

 

óÜÆîá£È¢

AP

üÈÊÕÙïî£

CP

 

 

ûâ×ä

US

ÐúÇ¡

CT

 

 

ØÙåô

CN

ÝÙîÀ

CO

 

 

ÚØ×Ä

DS

É´Øæ

DL

 

 

EmailTemplate

ET

ּ̽ɩÐú

DP

 

 

öÊ̽

ER

ØôÆî

DS

 

 

ExtractTask

EX

á¸ÊÖÝÙîÀ

DC

 

 

Identity Manager Ú¨æÀ

LA

ÚöÆî

EN

 

 

IDMX ËðÆîϯ

UX

ÙÚÈç

LN

 

 

LoadConfig

LD

ã¾Åø

EP

 

 

LoadTask

LT

ã¾Ä«

IM

 

 

LoginConfig

LC

List

LI

 

 

á¬Ü©

PO

ç¥Ä«

LD

 

 

É©ÐúÉ¢äÆ

PT

àôÄ«

LG

 

 

æñäã

RS

ÊÕä»

MO

 

 

æñäãÚ¨æÀ

RA

àôÅø

LO

 

 

æñäãÏÐÞÌ

RF

ÆÛñ¢üÈÊÕ

NC

 

 

æñäãÎìǵ

RE

É¢äÆÑ¥

PT

 

 

RiskReportTask

RR

É¢äÆЩ

PE

 

 

Role

RL

É©Ðú

PV

 

 

Rule

RU

ÓìÝÃÙïî£

RP

 

 

ËðÆîϯ

US

Óìä»É©Ðú

RV

 

 

TaskDefinition

TD

ÍÜáº

RJ

 

 

TaskInstance

TI

ÜÜÅÏ

TR

 

 

TaskSchedule

TS

usernameRecovery

UR

 

 

TaskTemplate

TT

 

 

 

 

TaskResult

TR

 

 

 

 

UserForm

UF

 

 

 

 

WorkItem

WI

 

 

 

 

XMLDATA

XD

 

 

 

 

ÔÏÇÞ

ÏР12-19 ë©ÍüħÇãæñÕèÕ»ÄãóÃÇôÒ³ùÃõïÇóÎûÔÏÇÞ¡¨

ÏР12-19 óÃÇôÒ³ùÃõïÇóÎûÔÏÇÞ

ÔÏÇÞÇØê¢

ÓÁÅÆ

æñÕèÕ»ùÃôúÇó

á¬Ü©ç°Ý½

Violation of policy {0} : {1}

PV

ðÕøýàÒÕæ

Invalid credentials

CR

ûâÓîÄâËÍ

Insufficient privileges

IP

æñÕèÕ»Çô̽ÆÂÚõ

Database access failed

DA

Ú¨æÀÄØØôÆî

Account disabled

DI


ËßÅÏî¨ÕøØ´òçöõÊÑ

ÚÀÆ«ÅèØÙåô Identity Manager ÅèËßÅÏÅèĶʰȢÎûî¨ÕøØ´òçöõÊÑ¡¨

ÍÔÈ´ Identity Manager î¨ÕøØ´òçÄãÎûØ´òçÉá̦ȴÙÄÄ¡Îû¡£áþÈùΤðÂÈÔÌùÎûÊ©ÇÄæÀÅèůشòçÌÏÊ©ÇÄæÀÎûÅûÙï÷ãౡ¤åµÚÀÐúÇ¡öõÊÑØþàÁÞÞÉËÕë¡¢ÆÆäÄè×ÊäÔ¶ÈùΤðÂÎûî¨ÕøØ´òçÚáßÀÅèĶÇÖâú¡¨

ØÙåôËßöõÊÑØ´òç

Ó¼ÓÑØÙåôËßöõÊÑØ´òç¡¢îùÙÚÈçÅèĶÊãüõ¡¨

  1. òÙ̽ [Reports] > [New] > [Audit Log Tampering Report]¡¢ÅèÐúÇ¡öõÊÑÞÞÉË¡¤
  2. åµüÏÆü [Define a Tampering Report] Ó÷Óò (îùÙ¶ïåè· 12-1) Õë¡¢Ò³ÞÞÉËòÓÄ«íº÷î¡¢àÓÑ¥ [Save] æÚÞÞÉË¡¤
  3. è· 12-1 ØÙåôî¨ÕøØ´òçöõÊÑÞÞÉË
    ØÙåôî¨ÕøØ´òçöõÊÑÞÞÉË

    ÚÀľƫÅèÑÀÌùÅèĶƫòÙÙ¶í°¡¨

    • ÞÞÉËèòÓÑ - òÓÄ«ÞÞÉËÎûë©ÍüÍÌèòÓÑ¡¤
    • ÈùΤð¡Ö<server_name>¡×ÎûØÄÌîÊ©ÇÄ - òÓÄ«ÈùΤðÂÎûØÄÌîÊ©ÇÄæÀ¡¤
    • ȺòÙâúÆ«üéÚÀÉ´Øæ÷®ÎûØ´òçâúÆøÈÔàÒëæÙò̧íºØ´Ò³öõÊÑ¡¢ËäÆ«ÅèÓî̱ÞÞÉËî¯ÞØÅèßÈØíÕæ×䡤
    • çÙÄÍâÓǵÞÞÉË - Æ«ÙòÞÞÉËá¸ÎªÝàç´çÙÄÍâÓǵã®ØÊÈÝÑÀÌùÎûçÙÄÍâÓǵÇâÉß¡¤
    • òÙ̽ȺòÙâúÕë¡¢Ó÷ÓòäÄÊÕä»ËäßÈÆüÚÀòÓÄ«çÙÄÍâÓǵÇâÉß¡¤ÈþÑÒîùØ´Èî¡¢Ýàç´çÙÄÍâÓǵã®ØÊÅÆÇóÄùÕ©ÑÒÄâÇøÇÀÎû - ÝÕíµÆ«×ääÄÒ­éÅñ¢Ùïæñع (ËóÇñÚ¨æÀ ID ÍÐÚ¨æÀñ¥á£Ø´òç)¡¤
    • åôßÐçßÝà PDF òÙâú - òÙ̽ȺòÙâúÆ«åôßÐȺÞÞÉËÎûçßÝà PDF òÙâú¡¤
    • ÜÚöþ - òÙ̽óÜ̦ȴȺÞÞÉËÄæÇô̽ûâÎûÜÚöþ¡¤
  4. ÚÙĶËôòÙ̽ [Configure] > [Audit]¡¢ÅèâäÚö [Audit Configuration] Ó÷Óò (Çñè· 12-2 ÍÔÆü)¡¤
  5. è· 12-2 ËßöõÊÑî¨ÕøØ´òçØÙåô
    ËðÆî [Audit Configuration] Ó÷ÓòØÙåôî¨ÕøËçǵ

  6. òÙ̽ [Use Custom Publisher]¡¢àÓѥѺġĶ [Repository publisher] ÝÙḡ¤
  7. òÙ̽ [Enable tamper-resistant audit logs]¡¢àÓѥѺġĶ [OK]¡¤
  8. ѺġĶ [Save] óÃÇôÝÃÌù¡¤
  9. ÚÀÆ«ÅèÇÂȹùÃÝðȺòÙâú¡¢ÈþÑÒÆÜøÜå÷ÎûâúÆøÆÛËÎÙòÇãî¨ÕøØ´òçöõÊÑÞÞÉËÄãâÐÈçíºØ´¡¢ÚÀÆÒâüÓìä»ØÙåôÞÞÉËÄß×äÍÁÜ©ÝÕËèâúÆø¡¤


ËðÆîÈÜÓÔàõÉ©á£È¢

Identity Manager Æ«ÅèÙòî¨ÕøËçǵßÈǨá¿ÈÜÓÔî¨ÕøàõÉ©á£È¢¡¤ßÈËòħÅèĶÈÜÓÔàõÉ©á£È¢¡¨

ÚÀÆ«ÇãÙ¶äùÄÖ̦ÜÚÄãÊÆ̯ÝÕËèàõÉ©á£È¢ÎûÔÏÌî¤Ù¶äùÄÖ̦ÜÚÄãõäßÈËòħ Javadoc ֪ȢÎûÄõÓòÅÆǵ¡¤

âäàõàõÉ©á£È¢

ÍÔÈ´àõÉ©á£È¢ÉáÆ«èÒÉ¢ AuditLogPublisher ÄõÓò¡¤(îùÙ¶ïå Javadoc¡¢Åè̽ڵȴùÃÄõÓòÎûæÛÜØæñع)¡¤âäàõϯƫÅèÍ·Èú AbstractAuditLogPublisher ùËɱ¡¤ÈºùËɱƫÔÈεØÙåôËäíýÏñÄØÒ³àõÉ©á£È¢ßÈËòÍÔÈ´ÆÒÓÑòÙâú¡¤(îùÙ¶ïåÙ¶äùÄÖ̦ÜÚÄãÎûàõÉ©á£È¢î¯Ëó)¡¤

àõÉ©á£È¢ÆÒâü̦ȴġԶàÒÅ¿í°Ðúé¬ÄÍ¡¤

ÆíÌÔâÎßæ

ÅèĶÊãüõë©ÍüħàõÉ©á£È¢ÎûÆíÌÔâÎß桨

  1. èÒËóŧÎìǵ¡¤
  2. ËðÆî setFormatter() ÅÉÎÎÝÃÌù֪Ȣŧá£È¢ (ÇñΪȴ)¡¤
  3. ËðÆî configure(Map) ÅÉÎÎßÈËòòÙâú¡¤
  4. ËðÆî publish(Map, LoggingErrorHandler) ÅÉÎÎàõÉ©Ëçǵ¡¤
  5. ËðÆî shutdown() ÅÉÎÎÜÜÅÏàõÉ©á£È¢¡¤

Identity Manager ÚöÙ¯ÅèůàÒï¢ÈôÕëÊÕä»î¨ÕøØÙåôÕë¡¢ÉáÙÚÈçÊãüõ 1 ̯ 3¡¤ÇñΪÇãÌËƵùÃÝðÄæЩÆÜܨÆíî¨ÕøËçǵ¡¢Ð¬ÄâÙÚÈçÊãüõ 4¡¤

ÇãÇÑÄ¡àõÉ©á£È¢Îìǵĸã¯ÌËƵġȹ configure(Map)¡¤(àõÉ©á£È¢àÒëæҳɢÆîÄãÎûØÙåôüÈÊÕØøäíÞ¬)¡¤ÊÕä»î¨ÕøØÙåôÑ¥¡¢ÓûÇ¿äÄùÃÝðÆøЩÎûàõÉ©á£È¢¡¢àÓÑ¥ÐúÇ¡ä»ÎûàõÉ©á£È¢¡¤

Êãüõ 3 ÄãÎû configure() ÅÉÎÎÆ«×ääÄÇ£Åø WavesetException¡¤ÇãȺÚÅÎÓĶ¡¢ÙòÍÁÜ©àõÉ©á£È¢¡¢ÅâÄâäÄè×ȺàõÉ©á£È¢âÐÈçǶÈô̧ÅìÌËƵ¡¤

ØÙåô

àõÉ©á£È¢Æ«ÅèÊôÈ´òÙâú¡¢Ä¾Æ«ÅèÈ´ÇéÔ¶òÙâú¡¤getConfigurationOptions() ÅÉÎÎÆ«ã®ÇßàõÉ©á£È¢ÅÅßÎÎûòÙâúÛÒÞÌ¡¤ÝÕËèòÙâúËðÆî PublisherOption ùËɱ (îùÙ¶ïå Javadoc Åè̽ڵȴùÃȺùËɱÎûæÛÜØæñع) âÐÈçÐìæÒ¡¤î¨ÕøØÙåôóôáþðÂÇãÐúåôàõÉ©á£È¢ÎûØÙåôÄõÓòÕëäÄÌËƵȺÅÉÎΡ¤

Identity Manager Æ«ÇãÈùΤðÂÚöÙ¯ÕëÌÏî¨ÕøØÙåôüÈÊÕÄæÑ¥ËðÆî configure(Map) ÅÉÎÎØÙåôàõÉ©á£È¢¡¤

âäàõ֪Ȣŧá£È¢

Ù¶äùÄÖ̦ÜÚÅýÉÖÅèĶ֪Ȣŧá£È¢ÎûÔÏÌî¨

֪Ȣŧá£È¢ÆÒâüèÒÉ¢ AuditRecordFormatter ÄõÓò¡¤ÈºÆÀ¡¢ÖªÈ¢Å§á£È¢ÆÒâü̦ȴġԶàÒÅ¿í°Ðúé¬ÄÍ¡¤îùÙ¶ïåÙ¶äùÄÖ̦ÜÚÄãÎû Javadoc¡¢Åè̽ڵæÛÜØæñع¡¤

â¡ÅõàõÉ©á£È¢/֪Ȣŧá£È¢

#ID#Configuration:SystemConfiguration ÎìǵÎûî¨ÕøúèÍÌÇÄÅøÍÔÈ´ÄØâ¡ÅõÎûàõÉ©á£È¢ÌÏ֪Ȣŧá£È¢¡¤Æ·È´ÝÕËèàõÉ©á£È¢ÌÏ֪Ȣŧá£È¢Æ«Çãî¨ÕøØÙåôËðÆîϯÄõÓòÄãËðÆ



ĸġÓ÷      Æøòç      ×ÄÅ¿      ĶġÓ÷     


ÅÆǵæÀ¨ 820-2292¡¤  Copyright 2007 Sun Microsystems, Inc. ÎêûâÍÔÈ´¡¤