Conceptual overview of simple realm administration
Implementation of simple realm administration
Simple realm administration is implemented using a context data item of the end-user and a context data item of a simple realm administrator. When both context data items have the identical realm value, the simple realm administrator and end-user are considered to be in the same realm. This enables the simple realm administrator to administer the end-user.
Simple realms are fully dynamic. A superadmin creates a new simple realm simply by creating a simple realm administrator for this realm.
With IAM 7.4 and later, the data attribute named realm has been added to the database schema context for both administrators and end-users to support simple realm administration. However, any string typed context data field may be used for the simple realms.
Optional simple realm prefix in usernames
Enforcing a simple realm prefix in usernames is an optional feature.
Advantages | Disadvantages |
|---|---|
|
|
To enable this feature, Username Prefill and Username Validator must be configured.
Simple realm administrator vs. superadministrator
Simple realm administrator | Superadministrator |
|---|---|
Simple realm administrators belong to exactly one realm.
| Superadministrators are not members of a realm.
|
Simple realm administrators can create:
| Superadministrators can create:
|
Simple realm prefill as convenience feature
This simple realm administration feature enforces the simple realm value regardless of what data a simple realm administrator provides in a create user dialog. For convenience, a simple realm prefill can be configured so that the simple realm administrator does not have to provide the simple realm value.
This feature was added to permit superadmins to also create users with simple realms in one step. If this is not required, the simple realm attribute can be omitted from the create user dialog by making the simple realm attribute optional in the User List/Search Page.
Known limitations
To enable the flexibility required for this feature, some limitations have to be accepted:
- Usernames must be unique across all simple realms. It is therefore possible that a simple realm administrator may try to enumerate users from another simple realm.
- Hardware tokens are shared across all simple realms. It is therefore possible that the same token is managed by simple realm administrators from different simple realms.