Authorization providers


The default authorization provider does not require special setup, and the default authorization engine makes all of the authorization decisions. WAS supports third-party security providers based on JACC v1.4, which includes annotations for propagating security policy information. If a JACC provider is used for authorization, Java EE authorization decisions are delegated to the JACC provider, but administrative authorization decisions are still made by the WAS default authorization engine.

Administrative components include...

Choose a JACC provider only when you want to work with an external security provider such as TAM.


Security Annotations


Authorization technology


