IBM Verify

IBM Verify

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only

Management Authorization - Role membership features

  • 1.  Management Authorization - Role membership features

    Posted 07/26/19 09:33 AM

    Hi community,

     

    We have stumbled across something that intrigued us. While we have some appliances on 9.0.6 that we upgraded from 9.0.3 to 9.0.4 to 9.0.5 then 9.0.6 (let's say group A), we also have "newer" (we switched from V7 to V9) appliances that we booted from 9.0.5 and on which we have applied the 9.0.6 fixpack (let's call them group B).

    While looking at Management Authorization, we observed some differences between group A and group B. Group A for example had all features for "Global Administrator" role at Write permission, like we supposed it would be. For the same role however, Group B had almost a third of it's features with no permission (None). We then read the following info in ISAM's documentation:

    "If you upgrade from a previous version of the appliance, new role membership features are set to None by default. Configure the permissions, if necessary."

    So, let's say we upgraded group A from previous 9.0.x versions; why and when did group A's permissions get fixed (we haven't set anything manually or in our Ansible automation code)? Is there anything to be done for group B to fix its permissions accordingly, or would we have to manually reset all of them? Is there a normalized way of doing this? Is it even supposed to be that far apart for this "Global Administrator" role (and that's just one example)?



    ------------------------------
    Regards
    Francis Laframboise

    ------------------------------