IBM Verify

IBM Verify

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Developing and testing in Production ISAM

    Posted 09/26/20 06:11 AM
    Is it possible to use an ISAM production appliance, by adding new features, without disrupting the components that are in production?

    Let's suppose I have a Reverse Proxy and a Policy Server that are running fine, in production. The customer does not have a Test or Quality environment!

    Later the customer asks me to add a new Reverse Proxy and add new features to the Policy Server that require development.
    Can I guarantee that these changes will not affect the Reverse Proxy, Policy Server, and other components that are running in Production (the only one he has)?

    In other words can I split the ISAM in different areas (much like domains in Domains in Datapower) so that one area does not affect the other?

    Does Policy Server Secure Domains help me on this?

    ------------------------------
    Joao Goncalves
    Pyxis, Lda.
    Sintra
    +351 91 721 4994
    ------------------------------


  • 2.  RE: Developing and testing in Production ISAM

    Posted 09/26/20 10:54 AM

    Hi Joao,

    When you create a new Reverse Proxy, its configuration is independent of other Reverse Proxies and so you can safely change its configuration without impact to any other.

    Each Reverse Proxy has its own branch in the policy object space so as long as you don't reuse ACLs or POPs across proxies, these can be changed too without impact.

    Users and Groups are shared by all Reverse Proxies so changes to group memberships will affect all components.

    The Federation and AAC runtime components are shared across the System so not easy to make changes to those things without risk of impacting existing configuration. 

    The secure domain function is used to create separate policy databases  for a form of multi tenancy.  Probably not useful for separation of config.

    To be honest I have to say that running a production Access Manager system without any dev or test environment is quite a risk.  How can new versions or upgrades be tested?  How can issues be recreated and fixed tested?

    Given it is possible to run a small Access Manager system on a reasonably speced laptop I think it should be easy to justify. 

    Jon  





    ------------------------------
    Jon Harry
    Consulting IT Security Specialist
    IBM
    ------------------------------