|
securityManager - For the Management of Users and User Rights in Spatial Data Infrastructures
sdi.suite securityManager helps organisations manage access constraints with respect to services and data in service-based Spatial Data Infrastructures. It restricts access to authorised users, and provides extensive functionality that enables the implementation of fine-grained authorisation concepts.
securityManager provides protection against unauthorised access for OGC WMS, WFS, WFS-T, WCS, as well as ESRI ArcGIS Server and ArcIMS services. Access constraints can be introduced either an the service function level or on the content (data) level. In addition, spatial authorisation serves to restrict functions and content to defined areas. By using the URL protection functionality, secured access to services, Web sites or Web applications can be provided.
Security interceptors are employed to check for authorisation to access geoservices. Thanks to the system's modular construction, these interceptors can be extended to allow for the incorporation of additional service types for protection by the securityManager. securityManager uses the OASIS XACML and SAML standards for describing policy sets, as well as for authentication and single sign-on purposes. In addition, a common access using "HTTP Basic Authentication" is possible. User and policy management in the securityManager can be performed via a browser-based administrative interface. It is also possible to incorporate existing user management systems such as LDAP by simple configuration.
licenseManager is the ideal addition to the securityManager. It provides the ability to allow users to electronically purchase commercial licenses for geoservices. securityManager and LicenseManager are available as a fully integrated bundle.
The modular structure securityManager, and its consistent compliance with IT standards, ensures that it is very easy to integrate into existing infrastructures and portals. As a result, securityManager is a highly integrable and expandable solution for controlling user constraints in service-based spatial data infrastructures.

User management |

Policy management |
|