After defining the specific components of an application that require protection, you can specify the roles that users may be assigned. Roles are the set of users who have access to a particular resource. These sets of users are defined by an expression.
Note: The following procedure assumes that you are creating an object. You can also copy the properties of an existing object to create an object. For more information, see Duplicate Policy Server Objects.
To create a role
The Create Role pane appears.
Employees
All employees of Acme Financial Services
TRUE
To form an expression, you can use the Expression Editor. To access the editor, click Edit.
Managers
Managers of Acme Financial Services
BOOLEAN(IsManager)
IsManager is the attribute mapping that was defined for the LDAP user directory.
Note: Click Help for descriptions of settings and controls, including their respective requirements and limits.
To make the human resources application more user friendly for employees of Acme Financial Services, you can configure a response that provides the employees ID on their benefit records.
To create a response that provides the employee ID:
The Create Response dialog opens.
Employee ID
Lists the employee ID.
The Create Response Attribute dialog opens.
WebAgent-HTTP-Header-Variable
User Attribute
Personnel_Key
EmployeeID
Note: Complete descriptions of response attributes exist in the Web Agent Configuration Guide.
The response named Employee ID has been created. When an employee views her benefits information, the data from this response is returned to the human resources application and her customer ID will be displayed in the benefits record.
After you have defined the resources and roles, you can group these objects into application security policies.
To create the application security policies
The Policies pane opens and displays a table listing the configured resources and roles. This table lets you quickly see which roles can be granted access to which resources.
You have created two security policies for the human resources application based on roles.
Note: If you need to edit resources or roles, you must make the changes on the respective tabs and not on the Policies pane.
Acme-financial.com wants to ensure that there is some descriptive information about the internal human resources application. Custom attributes can be used to define metadata that describes the application.
The information that Acme-financial wants for the purpose of the application and the date the application was completed.
Follow these steps:
The Custom Attributes dialog opens.
A table appears with Name and Value fields.
App_Completed
November_22_2007
Purpose
Human_Resource_Mgmt
Copyright © 2012 CA.
All rights reserved.
|
|