Conceptual overview of simple realm administration

Implementation of simple realm administration

Simple realm administration is implemented using a context data item of the end-user and a context data item of a simple realm administrator. When both context data items have the identical realm value, the simple realm administrator and end-user are considered to be in the same realm. This enables the simple realm administrator to administer the end-user.

 
Info

Simple realms are fully dynamic. A superadmin creates a new simple realm simply by creating a simple realm administrator for this realm.

With IAM 7.4 and later, the data attribute named realm has been added to the database schema context for both administrators and end-users to support simple realm administration. However, any string typed context data field may be used for the simple realms.

Optional simple realm prefix in usernames

Enforcing a simple realm prefix in usernames is an optional feature.

Advantages

Disadvantages

  • A simple realm prefix prevents username duplicates across simple realms.
  • A simple realm prefix reduces the risk of enumeration attacks.
  • The user must provide the username including the simple realm prefix on the login screen.
  • A simple realm prefix is not required with usernames that are unique by design (e.g., e-mail address).

To enable this feature, Username Prefill and Username Validator must be configured.

Simple realm administrator vs. superadministrator

Simple realm administrator

Superadministrator

Simple realm administrators belong to exactly one realm.

  • The simple realm attribute must be set.

Superadministrators are not members of a realm.

  • The simple realm attribute must be empty.

Simple realm administrators can create:

  • end-users in their own simple realm (requires proper authorization).

Superadministrators can create:

  • other superadministrators,
  • simple realm administrators, and
  • users in all simple realms (requires proper authorization).

Simple realm prefill as convenience feature

This simple realm administration feature enforces the simple realm value regardless of what data a simple realm administrator provides in a create user dialog. For convenience, a simple realm prefill can be configured so that the simple realm administrator does not have to provide the simple realm value.

This feature was added to permit superadmins to also create users with simple realms in one step. If this is not required, the simple realm attribute can be omitted from the create user dialog by making the simple realm attribute optional in the User List/Search Page.

Known limitations

To enable the flexibility required for this feature, some limitations have to be accepted:

  • Usernames must be unique across all simple realms. It is therefore possible that a simple realm administrator may try to enumerate users from another simple realm.
  • Hardware tokens are shared across all simple realms. It is therefore possible that the same token is managed by simple realm administrators from different simple realms.

Further information and links