IBM Tivoli Monitoring > Version 6.3 Fix Pack 2 > Administrator's Guide > Use role-based authorization policies > Policy management scenarios

IBM Tivoli Monitoring, Version 6.3 Fix Pack 2


Create and assign policy distributor roles

When you setup a new dashboard environment, user IDs must be created in the LDAP user registry for each dashboard user and policy administrator. You also need a user ID that is granted permission to distribute policies. This user ID must be specified when enabling authorization policies in the portal server. The portal server includes that user ID in the requests that it sends to the Authorization Policy Server to download the latest authorization policies. The Authorization Policy Server verifies that the user has permission to retrieve the policies. IBM Tivoli Monitoring provides the predefined PolicyDistributor role that has this permission already. Administrators can create new roles with this permission, or use the predefined role.


Any roles that are used for policy distribution must have the following permission:

Policy distribution permission definition
Parameter Value
Operation 'distribute'
Object Type 'role'
Resource Type 'rolegroup'
Resource 'default'


Procedure


Parent topic:

Policy management scenarios

+

Search Tips   |   Advanced Search