Local operating system settings

Use this page to configure local operating system registry settings.

To view this administrative console page, complete the following steps:
  1. Click Security > Global security.
  2. From User account repository, click the Available realm definitions drop-down list, then select Local operating system.
  3. Click Configure.

WebSphere® Application Server Version 7.0 distinguishes between the user identities for administrators who manage the environment and server identities for authenticating server to server communications. In most cases, server identities are automatically generated and are not stored in a repository.

[AIX Solaris HP-UX Linux Windows]However, if you are adding a previous version node to the latest version cell and the previous version node used a server identity and password, you must ensure that the server identity and password for the previous version are defined in the repository for this cell. Enter the server user identity and password on this panel.

[z/OS]Avoid trouble: Any settings that are related to the System Authorization Facility (SAF) might not be visible on this panel. To modify these settings:
  1. Go to the panel for SAF by clicking Security > Global security > External authorization providers.
  2. Select System Authorization Facility (SAF) from the drop-down list under the Authorization provider option.
  3. Click Configure.
[z/OS]

Custom properties

On the custom properties panel, you can add a value for one or more of the following custom properties:
disable.principal.case.preservation
Setting this property forces the principal returned by getRemoteUser() and getUserPrincipal() calls to be capitalized. If this property is not set, the case that was presented will be preserved.
force.credential.creation.for.validation
Setting this property forces the creation of an access control environment elements (ACEE) or find the ACEE of the user from the cache during ID assertion login to prevent obtaining information for users that have been revoked.
Avoid trouble: Forcing the creation of credentials all the time will cause a decrease in performance.
com.ibm.security.SAF.truncatePassword
Setting this property causes passwords that are longer than eight characters to be truncated to the first eight characters.

Primary administrative user name

Specifies the name of a user with administrative privileges that is defined in your local operating system.

The user name is used to log on to the administrative console when administrative security is enabled..
Attention: In WebSphere Application Server, Version 6.1 and later, a single user identity is required for both administrative access and internal process communication. When migrating to Version 6.1 and later, this identity is used as the server user identity. You need to specify another user for the administrative user identity.
[z/OS]Important: If System Authorization Facility (SAF) authorization is enabled on the External authorization providers panel, this field does not display.

Automatically generated server identity

Enables the application server to generate the server identity, which is recommended for environments that contain only Version 6.1 or later nodes. Automatically generated server identities are not stored in a user repository.

Information Value
Default: Enabled
[AIX Solaris HP-UX Linux Windows][IBM i]

Server identity that is stored in the repository

Specifies a user identity in the repository that is used for internal process communication. Cells that contain Version 6.1 or later nodes require a server user identity that is defined in the active user repository.

Information Value
Default: Enabled
[z/OS]

User identity for the z/OS started task

Specifies the user identity that is associated with the z/OS system started task. Each controller and server can have its own identity.

[AIX Solaris HP-UX Linux Windows]

Server user ID or administrative user on a Version 6.0.x node

Specifies the user ID that is used to run the application server for security purposes.

[AIX Solaris HP-UX Linux Windows]

Password

Specifies the password that corresponds to the server ID.