The SOA Security Manager Policy Server is an extended version of the CA SiteMinder r12.0 SP3 Policy Server that provides a centralized, policy-based security management operating environment for SOA deployments. As such, the Policy Server is the Policy Decision Point (PDP) in the SOA Security Manager environment.
The Policy Server integrates with SOA Agents and other CA access and identity management products and agent types to provide a single platform for securely managing every aspect of a business.
The Policy Server provides the following:
The Policy Server supports a range of authentication methods.
The Policy Server is responsible for managing and enforcing access control rules established by the Policy Server administrator. These rules define the operations that are allowed for each protected resource.
The Policy Server can be configured using the SOA Security Manager Administrative UI. The Administration service of the Policy Server allows the Administrative UI to record configuration information in the Policy Store.
The Policy Server generates log files that contain auditing information about the events that occur within the system. These logs can be printed in the form of predefined reports, so that security events or anomalies can be analyzed.
The Policy Server provides features for monitoring activity throughout a SOA Security Manager deployment.
In a SOA Security Manager implementation, a web service client sends a web service request in the form of an XML/SOAP message. At the target server, that request is intercepted by a SOA Agent. The SOA Agent determines whether the resource is protected, and if so, gathers user credentials from the request and passes them to the Policy Server.
The Policy Server authenticates the user against native user directories, then verifies if the authenticated user is authorized for the requested resource based on rules and policies contained in the Policy Store. Once a user is authenticated and authorized, the Policy Server grants access to protected resources and delivers permission and entitlement information.
| Copyright © 2011 CA. All rights reserved. | Email CA Technologies about this topic |