CA SiteMinder® supports the following policy models:
For example, you can protect the SharePoint root site with a policy domain. If you have document libraries that you want to protect with CA DataMinder, create applications for those libraries. In this situation, use the same agent or agent group in both the policy domain and the application.
A policy domain is a logical grouping of resources associated with one or more user directories. Policy domains contain realms, rules, responses, and policies (and optionally, rule groups and response groups).
The resources in a policy domain can be grouped in one or more realms. Rules control access to resources, that are associated with the realm that contains the resource. By grouping realms and rules in a policy domain, you can provide a secure domain for your resources.
For example, on a SharePoint site, some resources require a higher level of security than other resources. Define a realm with a higher level of security than uses an authentication scheme such as a certificate-based scheme. Use a realm with basic authentication for the less sensitive resources. For example, a common set of users wants to access both types of resources. You can group both realms in the same policy domain.
Follow these steps:
The Create Domain pane opens.
The Create Domain Task is submitted for processing.
Add your user directories to a policy domain. The Policy Server authenticates users by comparing the credentials to the credentials that are stored in the user directories.
Follow these steps:
The Choose user directories pane opens.
The user directory is removed from the list of Available Members and added to the list of Selected Members.
The selected user directory is added to the domain.
Realms are groupings of resources in a specific location on your network. CA SiteMinder® <agents> protect the resources in a realm. When users request resources within a realm, the associated Agent for SharePoint authenticates the user. The realm uses the authentication scheme you configured. The SharePoint server authorizes the user.
Because most SharePoint resources are URL-based, define the URLs of your SharePoint resources that you want to protect. Use the following examples as guides:
Follow these steps:
The Create Realm: Select Domain pane appears.
The Create Realm: Define Realm pane appears.
The Select an Agent screen appears.
Important: Do not add the 4.x agent object to any agent group, realm, or policy. This agent object exists only to support the internal operations of the CA SiteMinder® Agent for SharePoint.
/affwebservices/redirectjsp/redirect.jsp
/ClaimsWS/services/WSSharePointClaimsServiceImpl
Note: We recommend protecting only URLs on SharePoint systems, not lists, or specific documents.
The Create Realm Task is submitted for processing.
You can create a rule that fires in response to specified Web agent actions. The rule allows or denies access to the resource it is protecting.
To create a rule
The Create Rule: Select Domain pane opens.
The Create Rule: Select Realm pane opens.
The Create Rule: Define Rule pane opens.
Note: If a realm does not exist for the resources that you want to protect, a rule cannot be created to protect those resources.
The Effective Resource updates to include the resource.
The Action List is populated with HTTP actions.
The Create Rule task is submitted for processing.
You can create a policy by adding it to a new or existing domain. Policies define relationships between users and resources.
Follow these steps:
The Modify Domain pane opens.
A list of domains that match the search criteria opens.
The Modify Domain: Name pane opens.
The Policies dialog opens.
The Create Policy: Name pane opens.
The User Directories dialog opens.
The Modify Domain: Name pane reopens.
The Modify Domain Task is submitted for processing.
You can add individual users, user groups, or both to a policy and can create a policy binding between the added users and the policy. When a user tries to access a protected resource, the policy verifies that the user is part of its policy binding. Then the policy fires the rules included in the policy to see if the user is allowed to access the resource.
Follow these steps:
The Domain pane appears.
The Modify Policy page appears.
The Modify Policy:Name page appears.
The User Directories pane opens and contains group boxes for each user directory that is associated with the policy domain.
In each user directory section, you can select Add Members, Add Entry, Add All. Depending on which method you use to add users to the policy, a dialog opens to let you add users.
Note: If you select Add Members, the User/Groups pane opens. Individual users are not displayed automatically. Use the search utility to find a specific user within one of the directories.
You can edit or delete a user or group by clicking the right arrow (>) or minus sign (-), respectively.
The User Directories pane reopens and lists the new users for the policy on the section of the user directory. The task of binding users to the policy is complete.
Rules indicate the specific resources included in a policy and whether to allow or deny access to the resources when the rule fires. Responses indicate the actions you want to occur when the rule fires.
Note: Add at least one rule or rule group to a policy.
Follow these steps:
The Rules page opens.
The Available Rules pane opens.
The Rules section lists the added rules and groups.
Note: To remove a rule or rule group from a policy, click the minus sign (-) to the right of the rule on the Rules section. To create a rule, click New Rule on the Available Rules pane.
CA SiteMinder® applications protect resources by combining access privileges with specific conditions. Users who have the privileges and meet the conditions are granted access to the resources they request.
This section describes creating an application with the following components:
These components meet the minimum requirements of the CA SiteMinder® Agent for SharePoint. We recommend creating few applications and components during evaluation, testing, or initial-deployment environments. You can add more applications and components at any time.
Note: Resources protected with CA DataMinder require applications. Do not use policy domains.
Follow these steps:
The applications screen appears.
The Create Application: screen appears, with the General tab selected.
The Select Agent or Agent Group screen appears.
Important: Do not add the 4.x agent object to any agent group, application, or component. This agent object exists only to support the internal operations of the Agent for SharePoint.
affwebservices/redirectjsp/redirect.jsp
Verify that the field begins with one forward slash as shown in the following example:
/affwebservices/redirectjsp/redirect.jsp
The Create Component screen appears, with the cursor in the Component Name field.
The Select Agent or Agent Group screen appears.
Important: Do not add the 4.x agent object to any agent group, application, or component. This agent object exists only to support the internal operations of the CA SiteMinder® Agent for SharePoint.
ClaimsWS/services/WSSharePointClaimsServiceImpl
/ClaimsWS/services/WSSharePointClaimsServiceImpl
The Choose user directories screen appears.
Your directory connections move to the Selected Members list.
The Choose user directories screen closes, and the Create Application: screen appears.
Note: The components in Steps 5 and 6 are the basic components the CA SiteMinder® Agent for SharePoint requires to operate. For testing or production environments, create components for the other SharePoint URLs resources you want to protect. Possible examples of components include the following items:
The application is created and a confirmation message appears.
CA SiteMinder® applications use resources to protect items in your SharePoint environment. These resources for CA SiteMinder® applications consist of the following parts:
Note: In the previous context, "resources" refers only to the rules and actions that are associated with CA SiteMinder® applications. Generally, resources indicate the protected items on a SharePoint server, such as URLs.
Follow these steps:
The applications screen appears, showing a list of applications.
The Modify Application: screen appears.
The Resources screen appears.
/affwebservices/redirectjsp/redirect.jsp
The General screen appears.
The General screen closes and the Resources screen appears.
The application resources are created and a confirmation message appears.
CA SiteMinder® applications use roles to define the users or groups or organizations to which you wish to grant access to your SharePoint resources.
Follow these steps:
The applications screen appears, showing a list of applications.
The Modify Application: screen appears.
The Roles screen appears.
The Create Role: screen appears.
The Create Role: screen closes, and the Modify Application: screen appears.
The Role is created and a confirmation message appears.
Polices combine application resources and roles to protect your SharePoint environment.
Follow these steps:
The applications screen appears, showing a list of applications.
The Modify Application: screen appears.
The Policies screen appears.
/affwebservices/redirectjsp/redirect.jsp
The Policies screen closes. The Modify Application screen appears with a confirmation message.
Copyright © 2014 CA.
All rights reserved.
|
|