Creating and managing security domains

An enterprise can have one or more security domains; each security domain has a security policy associated with it. The Enterprise Security installation automatically creates a root organization and a default domain. The default domain contains the root organization, and a predefined security policy is associated with the default domain.

In each domain, you can create one or more suborganizations to represent the departments within your organization—see “Managing organizations and suborganizations”.

Table 5-1 describes the permissions you must have to manage security domains.

Table 5-1: Permissions required to manage security domains

Action

Permissions required

Create a security domain.

WRITE on the domain controlling asset in the domain that contains the root organization.

List the properties of a security domain.

LIST on the domain controlling asset.

Update the properties of a security domain.

READ and UPDATE on the domain controlling asset.

List the organizations in a security domain.

LIST on the organization controlling asset.

Delete a security domain.

READ and DELETE on the domain controlling asset.

StepsCreating a security domain

  1. In the left pane of Enterprise Security Manager, under Configure, select Domains, and click New.

  2. In the Create New Security Domain dialog box, enter:

    For information about implementing a new security policy, see “Managing security policies”.

StepsEditing a security domain

To edit the domain name, domain policy name, or domain description:

  1. In the middle pane of Enterprise Security Manager, highlight the domain you want to edit. In the right pane, right-click and select Edit Domain.

  2. In the Edit Domain dialog box, edit the values you want to change, and click OK.

StepsConfiguring general properties for a security domain

  1. In the middle pane of Enterprise Security Manager, highlight the domain you want to configure. In the right pane, right-click and select Configure General Properties.

  2. In the Configure Domain General Properties dialog box, enter these values, then click OK:

    WARNING! Do not select Notify Audit Events until after you set up both the message service and the message topic in your application server; otherwise, you will not be able to log in to Enterprise Portal—see “Setting up JMS auditing notifications for EAServer”.

StepsConfiguring lock manager properties for a security domain

  1. In the middle pane of Enterprise Security Manager, highlight the domain you want to configure. In the right pane, right-click and select Configure Lock Manager.

  2. In the Configure Domain Lock Manager Properties dialog box, enter these values, then click OK:

StepsConfiguring password properties for a security domain

  1. In the middle pane of Enterprise Security Manager, highlight the domain you want to configure. In the right pane, right-click and select Configure Password Properties.

  2. In the Configure Domain Password Properties dialog box, enter these values, then click OK:

StepsConfiguring account properties for a security domain

  1. In the middle pane of Enterprise Security Manager, highlight the domain you want to configure. In the right pane, right-click, and select Configure Account Properties.

  2. In the Configure Domain Account Properties dialog box, enter these values, then click OK:

StepsRegistering a security policy

Registering a security policy does not assign the policy to a specific domain.

  1. In the middle pane of Enterprise Security Manager, highlight All Domains. In the right pane, right-click, and select Register Policy.

  2. In the Register Policy dialog box, enter the name of the class that implements the security policy. For example, the name of the class that implements the default security policy is com.sybase.ep.security.policy.impl.DomainAssetsPolicy.

  3. Restart the application server.

  4. To apply this security policy to a domain, edit the domain, and set Domain Policy Name to the class name you specified in step 2—see “Editing a security domain”.

StepsListing the organizations in a security domain

  1. In the middle pane of Enterprise Security Manager, highlight the domain you want to configure. In the right pane, right-click, and select List Organizations.

  2. The dialog box that opens displays a list of the organizations in the current domain.