JACC registration of the provider implementation classes

 

JACC registration of the provider implementation classes

The JACC specification states that providers can plug in their provider using the system properties javax.security.jacc.policy.provider and javax.security.jacc.PolicyConfigurationFactory.provider system properties.

The javax.security.jacc.policy.provider property is used to set the policy object of the provider, while the javax.security.jacc.PolicyConfigurationFactory.provider property is used to set the provider PolicyConfigurationFactory implementation.

Although both system properties are supported in WebSphere Application Server, it is highly recommended that you use the configuration model that is provided. You can set these values using either the JACC configuration panel (see Authorizing access to J2EE resources using Tivoli Access Manager for more information) or by using wsadmin scripting. One of the advantages of using the configuration model instead of the system properties is that the information is entered in one place at the cell level, and is propagated to all nodes during synchronization. Also, as part of the configuration model, additional properties can be entered, as described in the JACC configuration panel.

Using the configuration model is especially recommended in the case of a Network Deployment (ND) environment where multiple application servers can exist in the configuration. If the system properties are used, ensure that each of the Java virtual machine (JVM) processes in the configuration set these properties. If the configuration model is used, the information is propagated to all processes through the synchronization process of the application server.



Related concepts

Authorization providers
Tivoli Access Manager integration as the JACC provider
JACC support in WebSphere Application Server
Authorization providers

Related tasks

Enabling an external JACC provider
Authorizing access to J2EE resources using Tivoli Access Manager
Propagating security policy of installed applications to a JACC provider using wsadmin scripting

Related reference

Interfaces that support JACC
Authorization provider troubleshooting tips


Searchable topic ID: rsec_jaccregister