IBM BS029ML Self Help Guide - Page 117

Document system changes, Set up a security audit on the system, User ID, Event name, What is logged

Page 117 highlights

Document system changes You should always document the system changes made, no matter whether it is a configuration change, or deployment of applications, or a Fix Pack or interim fixes. The change logs should be made available online, such that other people have access to them later even after you have left the project. The change journal or log can be as simple as the ones shown in Table 4-3. Table 4-3 Configuration change log Date User ID Apr 5, 2007 wpsadmin Apr 20, 2007 janedoe Aug 7, 2007 wpsadmin Sep 9, 2007 wpsadmin What Transferred database from Cloudscape to DB2. Installed Employee portlet application. Reconfigured security. Ran XMLaccess import to fix page order. You can add more information in the "What" column if you wish. Always make a backup copy of the files you are going to change and save them to a separate location or a different hard drive. The change log and these backup files should provide sufficient knowledge to recover the system in case something goes wrong. Do not to make multiple major changes at the same time. For example, do not configure HTTP over SSL and TAM integration at the same time. Before making any major changes, such as installing or upgrading the system or configuration changes, you should always back up the system, including the database, LDAP, and the file system. You should try to make these backups approximately at the same time, if possible. See Appendix B, "Maintenance: Fix strategy, backup strategy, and migration strategy" on page 207 for details. Set up a security audit on the system We highly recommend the AuditService be enabled all the time on all system environments. For user and group management and portal access control purposes, we suggest the events list shown in Table 4-4. Table 4-4 audit log Event name audit.groupEvents audit.userEvents What is logged Group creation, modification, and deletion User creation, modification, and deletion audit.ownerEvents audit.resourceEvents audit.userInGroupEvents Owner change of a resource Resource creation, modification, and deletion addition of a user to a group Chapter 4. WebSphere Portal security 103

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242

Chapter 4. WebSphere Portal security
103
Document system changes
You should always document the system changes made, no matter whether it is a
configuration change, or deployment of applications, or a Fix Pack or interim fixes. The
change logs should be made available online, such that other people have access to them
later even after you have left the project.
The change journal or log can be as simple as the ones shown in Table 4-3.
Table 4-3
Configuration change log
You can add more information in the “What” column if you wish. Always make a backup copy
of the files you are going to change and save them to a separate location or a different hard
drive. The change log and these backup files should provide sufficient knowledge to recover
the system in case something goes wrong.
Before making any major changes, such as installing or upgrading the system or
configuration changes, you should always back up the system, including the database, LDAP,
and the file system. You should try to make these backups approximately at the same time, if
possible. See Appendix B, “Maintenance: Fix strategy, backup strategy, and migration
strategy” on page 207 for details.
Set up a security audit on the system
We highly recommend the AuditService be enabled all the time on all system environments.
For user and group management and portal access control purposes, we suggest the events
list shown in Table 4-4.
Table 4-4
audit log
Date
User ID
What
Apr 5, 2007
wpsadmin
Transferred database from Cloudscape to DB2.
Apr 20, 2007
janedoe
Installed Employee portlet application.
Aug 7, 2007
wpsadmin
Reconfigured security.
Sep 9, 2007
wpsadmin
Ran XMLaccess import to fix page order.
Do not to make multiple major changes at the same time. For example, do not configure
HTTP over SSL and TAM integration at the same time.
Event name
What is logged
audit.groupEvents
Group creation, modification, and deletion
audit.userEvents
User creation, modification, and deletion
audit.ownerEvents
Owner change of a resource
audit.resourceEvents
Resource creation, modification, and deletion
audit.userInGroupEvents
addition of a user to a group