6.4. Identity Assertion

Definition

Identity assertion is basically the process taking place when the invocation credential is asserted to the downstream server during a call.

When a client authenticates to a server, the received credential is set. When authorization checks the credential to see if it is allowed access, it will also set the invocation credential so that if the EJB method calls another EJB method located on other servers, the invocation credential can be used as the identity to invoke the downstream method. Depending on the RunAs ...

Get IBM WebSphere V5.0 Security: WebSphere Handbook Series now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.