IBM DataPower Operations Dashboard v1.0.20.x

A newer version of this product documentation is available.

You are viewing an older version. View latest at IBM DPOD Documentation.

Security Roles

The screen is accessible by clicking [Manage→Security→Roles] from The Navigation Bar.

The security roles management screen is always available, regardless of whether the system is managing users using DPOD internal database registry or LDAP.

Security roles are used to provide a means for the administrator to limit the functionality and filter the view users have of the system. For example, administrators can use the roles to limit a user for view-only functionality, as well as filter out devices, domains, services, client IP addresses, APIs, payload and more from a user's view, thereby providing each user with insights to only the parts of the system they are allowed to access.

There are two types of security roles available with DPOD:

  • Built-in Roles - DPOD's pre-defined roles, which can not be added, deleted or altered.

  • Custom Roles - defined by the administrator, and may be added, deleted or altered by a DPOD administrator.

For a detailed explanation about security roles, see Role Based Access Control.

Custom Roles Table

The custom roles widget at the top of the screen lists the custom roles defined in the system in a table. Each row in the table contains the following information for a single role:

Column

Description

Column

Description

Name

The role's name. 
Clicking on a role's name will load the role's details in the Role View and provide access to system actions for the role. 

Description

The description for this role

Adding a Custom Role

The custom roles table widget contains the Add Custom Role button at the top.
Click this button to add a new custom role in the system.

The Role Details section below provides information about the details required for adding or editing custom roles.

Built-In Roles Table

The built-in roles widget at the top of the screen lists the built-in roles defined in the system in a table. Each row in the table contains the following information for a single role:

Column

Description

Column

Description

Name

The role's name. 
Clicking on a role's name will load the role's details in the Role View and provide access to system actions for the role. 

Description

The description for this role

Role View

The role view is loaded for a role when the role's name is clicked from the Built-In Roles Table described above.

The system displays the following details:

Detail

Content Description

Detail

Content Description

Name

The name of this role

Description

The description of this role.



Groups in Role

This widget lists all the Security Groups assigned to this role.
You may use the controls in this widget to remove or add a group association to this role.

If you are using an LDAP registry, please use the LDAP group name.

Users in Role

This widget lists all the Users assigned to this role.
You may use the controls in this widget to remove or add a user association to this role.

If you are using an LDAP registry, please use the authenticated LDAP user name.

Custom Role View

The custom role view is loaded for a role when the role's name is clicked from the Custom Roles Table described above.

The system displays the following details:

Detail

Content Description

Detail

Content Description

Name

The name of this role

Description

The description of this role.

General



Access API-C Product View

Whether this role, when assigned to a user, allows them to access the API-C product view.

Access Gateway Product View

Whether this role, when assigned to a user, allows them to access the Gateway product view.

Access Expert Mode

Whether this role, when assigned to a user, allows them to access the OpenSearch Dashboards.

View Reports / Alerts

Whether this role, when assigned to a user, allows them to view reports and alerts.

Edit Reports / Alerts

Whether this role, when assigned to a user, allows them to edit reports and alerts.

Transactional Information



Allow Access to Raw Messages

Whether this role, when assigned to a user, allows them to view Logs Table, Logs Dashboard or raw messages of transactions.

Allow Access to Payload

Whether this role, when assigned to a user, allows them to view Messages Payload.

Allow Manage Payload Capture

Whether this role, when assigned to a user, allows them to manage payload capture.

Allow Viewing Correlated Trans.

Whether this role, when assigned to a user, allows them to access the "Correlated Trans." tab in the Single Transaction Page (both Gateway and API-C)

Allow Viewing Correlated Trans. Raw Errors

Whether this role, when assigned to a user, allows them to access the "Raw Errors" window, in the "Correlated Trans." tab, in the Single Transaction Page (both Gateway and API-C)

Allow Validate Remote WSDL

Whether this role, when assigned to a user, allows them to perfrom the action in DevOps Services List

Allow Promote Remote WSDL

Whether this role, when assigned to a user, allows them to perfrom the action in DevOps Services List

Allow WSDL URL Change

Whether this role, when assigned to a user, allows them to perfrom the action in DevOps Services List

Validate Local WSDL

Whether this role, when assigned to a user, allows them to perfrom the action in DevOps Services List

Promote Local WSDL

Whether this role, when assigned to a user, allows them to perfrom the action in DevOps Services List

Stop/Start Service

Whether this role, when assigned to a user, allows them to perfrom the action in DevOps Services List

Allowed Resources



General

Lists of general resources this role provides access to or All if no resources defined (relevant to IDG and API-C data). 
The resources in this section are "Device" and "Client IP".

DataPower Gateway

Lists of resources this role provides access to or All if no resources defined (relevant only to IDG data). 
The resources in this section are "Domain" and "Service".

API Connect

Lists of resources this role provides access to or All if no resources defined (relevant only to API-C data). 
The resources in this section are "Provider Org Name", "Catalog Name", "Space Name", "Product Name", "Plan Name", "API Name", "Consumer Org Name", "App Name" and "Client ID".

Denied Resources



General

Lists of general resources this role denies access to or None if no resources defined (relevant to IDG and API-C data). 
The resources in this section are "Device" and "Client IP".

DataPower Gateway

Lists of resources this role denies access to or None if no resources defined (relevant only to IDG data). 
The resources in this section are "Domain" and "Service".

API Connect

Lists of resources this role denies access to or None if no resources defined (relevant only to API-C data). 
The resources in this section are "Provider Org Name", "Catalog Name", "Space Name", "Product Name", "Plan Name", "API Name", "Consumer Org Name", "App Name" and "Client ID".



Groups in Role

This widget lists all the Security Groups assigned to this role.
You may use the controls in this widget to remove or add a group association to this role.

If you are using an LDAP registry, please use the LDAP group name.

Users in Role

This widget lists all the Users assigned to this role.
You may use the controls in this widget to remove or add a user association to this role.

If you are using an LDAP registry, please use the authenticated LDAP user name.

Edit or Delete a Custom Role

When viewing the details of a customer role, the Role View screen contains two buttons at the top.

Click the Edit button to edit the displayed role's details.

Click the Delete Custom Role button to remove the custom role from the system.

Role Details

When adding or editing a custom role, you will need to provide the following details:

Detail

Content Description

Detail

Content Description

Name

The name of this role

Description

The description of this role.

General



Access API-C Product View

Whether this role, when assigned to a user, allows them to access the API-C product view.

Access Gateway Product View

Whether this role, when assigned to a user, allows them to access the Gateway product view.

Access Expert Mode

Whether this role, when assigned to a user, allows them to access the OpenSearch Dashboards.

View Reports / Alerts

Whether this role, when assigned to a user, allows them to view reports and alerts.

Edit Reports / Alerts

Whether this role, when assigned to a user, allows them to edit reports and alerts.

Transactional Information



Allow Access to Raw Messages

Whether this role, when assigned to a user, allows them to view Logs.

Allow Access to Payload

Whether this role, when assigned to a user, allows them to view Messages Payload.

Allow Manage Payload Capture

Whether this role, when assigned to a user, allows them to manage payload capture.

Allow Validate Remote WSDL

Whether this role, when assigned to a user, allows them to perfrom the action in DevOps Services List

Allow Promote Remote WSDL

Whether this role, when assigned to a user, allows them to perfrom the action in DevOps Services List

Allow WSDL URL Change

Whether this role, when assigned to a user, allows them to perfrom the action in DevOps Services List

Validate Local WSDL

Whether this role, when assigned to a user, allows them to perfrom the action in DevOps Services List

Promote Local WSDL

Whether this role, when assigned to a user, allows them to perfrom the action in DevOps Services List

Stop/Start Service

Whether this role, when assigned to a user, allows them to perfrom the action in DevOps Services List

Allowed Resources



General

Lists of general resources this role provides access to or All if no resources defined (relevant to IDG and API-C data). 
The resources in this section are "Device" and "Client IP".

DataPower Gateway

Lists of resources this role provides access to or All if no resources defined (relevant only to IDG data). 
The resources in this section are "Domain" and "Service".

API Connect

Lists of resources this role provides access to or All if no resources defined (relevant only to API-C data). 
The resources in this section are "Provider Org Name", "Catalog Name", "Space Name", "Product Name", "Plan Name", "API Name", "Consumer Org Name", "App Name" and "Client ID".

Denied Resources



General

Lists of general resources this role denies access to or None if no resources defined (relevant to IDG and API-C data). 
The resources in this section are "Device" and "Client IP".

DataPower Gateway

Lists of resources this role denies access to or None if no resources defined (relevant only to IDG data). 
The resources in this section are "Domain" and "Service".

API Connect

Lists of resources this role denies access to or None if no resources defined (relevant only to API-C data). 
The resources in this section are "Provider Org Name", "Catalog Name", "Space Name", "Product Name", "Plan Name", "API Name", "Consumer Org Name", "App Name" and "Client ID".









Copyright © 2015 MonTier Software (2015) Ltd.