Previous Topic: Proxy Configuration

Next Topic: Logging

Proxy Administration Support

You can configure a proxy ID for all tasks accomplished within CA Identity Manager. Previously, a proxy ID could only be configured for use with requests generated from the SAWI interface. This proxy ID is maintained on the main Endpoint page in the Proxy Administration Configuration section. The proxy ID can be used for any type of CA Identity Manager request against supported objects, and for any Identity Manager Administrator that is logged on.

Note: The enhancement is only recommended to use after careful consideration (and preparation) of the following consequences:

  1. Any Global User (with the proper privileges provided within CA Identity Manager) is able to administer RACF Userids, Groups, and Permissions under the configured proxy ID. Any mainframe security product scoping is lost; only the scoping of the proxy ID is enforced.
  2. As mentioned above, security settings are now the only point of enforcement against a Global User manipulating mainframe security data.
  3. Any reports or auditing methods against administration of your mainframe security data that originate from the mainframe is now compromised; the only ID that shows up for any administration that occurred from CA Identity Manager is the configured proxy ID.
  4. If the proxy ID's password changes on the mainframe, the password must be changed on every Endpoint Page within the Provisioning Manager that it is configured for.

By default, the Connector operates in the same mode as in past releases; the logged-on Global User and their password are used for submitting any requests destined to the mainframe security product. The common endpoint page entitled Endpoint Settings provides two checkbox controls under the description Administrator Credentials that control the three possible settings:


Copyright © 2010 CA. All rights reserved. Email CA about this topic