Database update and polling concepts

The ISAM policy server (pdmgrd) manages the master authorization policy database and maintains location information about other ISAM servers in the secure domain. An administrator can make security policy changes to the secure domain at any time. The policy server makes the necessary adjustments to the master authorization database whenever security policy changes are implemented. When the policy server makes a change to the master authorization database, it can send out notification of this change to all replica databases in the secure domain that support individual policy enforcers (such as WebSEAL). The policy enforcers must then request an actual database update from the master authorization database.

WebSEAL, as a resource manager and policy enforcer, has three options to obtain information about authorization database changes:

The [aznapi-configuration] stanza of the WebSEAL configuration file contains stanza entries for configuring update notification listening and database polling.

Parent topic: Configuration of authorization database updates and polling