Previous Topic: Configure the Logon ShieldNext Topic: Define a Realm


How to Use the ENC Authorization Rules Configuration View

The ENC Authorization Rules configuration view lets you view or edit ENC tables and their associated contents. The ENC Authorization component uses these tables to enforce permissions and access control for all communications and operations in the ENC environment.

Note: Unlike other policy groups, there is no direct access to the underlying ENC authorization tables from the configuration policy editor, that is, the dynamic Setting Properties and Modify Properties dialogs. Therefore, you must use the ENC Authorization Rules configuration view, which handles inter-table dependencies and provides pre-commit evaluation of the specified rules.

This view consists of a main dialog, ENC Authorization Rules, with five tab pages—one each for the configuration policies associated with the following tables:

Note: See the Implementation Guide for an expansive overview of the terms and usage of authorization within the ENC environment.

The basic steps for using the ENC Authorization Rules configuration view are as follows:

  1. Define the realms in use within your ENC infrastructure.
  2. Specify the secured objects or security principals that are mapped to given realms.
  3. Define time ranges for all Access Control Entries (ACEs).
  4. Define the Timed Access Control List (TACL).
  5. Define a white list of IP addresses or IP address ranges that are allowed to establish connections within your ENC infrastructure.

If there are no authorization rules configured to allow a specified event to occur, then access will be denied for that event. Note that initially no rules are defined, hence all access is denied.

More information:

ENC Authorization Rules Policy Group