Before you begin, note the following:
- Only system administrators can add, modify and remove users and roles. To set up administrators, see Realm Configuration.
Your product has a primary user store where the users/roles that you create using the management console are stored by default. It's default
RegEx
configurations are as follows.RegEx
configurations ensure that parameters like the length of a user name/password meet the requirements of the user store.PasswordJavaRegEx-------- ^[\S]{5,30}$ PasswordJavaScriptRegEx-- ^[\S]{5,30}$ UsernameJavaRegEx-------- ^~!#$;%*+={}\\{3,30}$ UsernameJavaScriptRegEx-- ^[\S]{3,30}$ RolenameJavaRegEx-------- ^~!#$;%*+={}\\{3,30}$ RolenameJavaScriptRegEx-- ^[\S]{3,30}$
When creating users/roles, if you enter a username, password etc. that does not conform to the
RegEx
configurations, the system throws an exception. You can either change theRegEx
configuration or enter values that conform to theRegEx
. If you change the default user store or set up a secondary user store, configure theRegEx
accordingly under the user store manager configurations in<AS_HOME>/repository/conf/user-mgt.xml
file.
Go to the relevant topic listed below for details:
Managing Users
This following topics explain how new user accounts can be added and managed using the management console of your product.
Adding a new user and assigning roles
To add a new user account and assign roles:
- Log in to the product management console.
- On the Configure menu, click Users and Roles. The User Management page appears.
Click Users. The Users page appears.
The Users link is only visible to users with the "Admin" permission. The Users page is used to add new user accounts and also modify or delete existing accounts if needed.
- Click Add New User. The Add User page appears.
- Select the domain. By default, PRIMARY will appear to indicate the primary user store; however, if secondary user stores have been added they will be listed in the Domain drop-down menu as well.
- Enter the username and password.
- If you want to add a user with the default "Internal/everyone" role, click Finish and you are done. Otherwise, click Next to define a user role and proceed to the next step.
- Enter a role name pattern. Use one of the following approaches:
- Enter the exact role name.
- Enter part of the role name followed by or preceded by an asterisk (*) (for example, t* - this option will return all the roles that have role names starting with "t".)
- Enter only an asterisk (*). This option will return all the roles under the selected domain.
- Click Search.
- Select the appropriate user roles.
- Click Finish.
A new user account will be created with the default/specified roles, while the username is displayed in the u ser list.
Importing users
In addition to manually adding individual users, you can import multiple users in bulk if you have exported them to a comma-separated values (.csv) file or Microsoft Excel (.xls) file.
This is only supported if you have configured your user store as JDBCUserStoreManager. See here for information on how to do this.
- On the Users screen, click Bulk Import Users.
- Browse and select the file that contains the user data.
- Specify a default password to assign to all the users you are importing and click Finish. This password is valid for only 24 hours, so you should inform your users that they must log in and change their password within 24 hours.
Searching for users
To search for users:
- Log in to the product management console.
- On the Configure menu, click Users and Roles. The User Management page appears.
- Click Users. The Users page appears.
- Select the user store domain.
- Enter a username pattern. Use one of the following approaches:
- Enter the exact username.
- Enter part of the username followed by or preceded by an asterisk (*) (for example, ad* - this option will return all the users that have usernames starting with "ad".)
- Enter only an asterisk (*). This option will return all the users under the selected domain.
- Click Search.
Editing users
User roles can be edited by either changing the user's password or by assigning more user roles.
To edit a user:
- Log in to the product management console.
- On the Configure menu, click Users and Roles. The User Management page appears.
Click Users. The Users page appears.
- Search for the user.
- To edit add more user roles:
- Click the corresponding Assign Roles link.
- Enter a role name pattern. Use one of the following approaches:
- Enter the exact role name.
- Enter part of the role name followed by or preceded by an asterisk (*) (for example, t* - this option will return all the roles that have role names starting with "t".)
- Enter only an asterisk (*). This option will return all the roles under the selected domain.
- Click Search.
- If you wish to edit the permissions of a selected role:
- Click the respective Permissions link.
- Select/De-select on the permissions that you wish to add/remove.
- Click Update.
- Select the respective roles that you wish to assign to the user.
- Click Update. Click OK, when a confirmation message appears.
- Click Finish. Click OK, when a confirmation message appears.
To edit a user's password:
You cannot change the username of an existing user.
- Click Change Password, respective to the selected user.
- Enter the new password and click Change.
- If the password change is successful, a message appears. Click OK.
Deleting a user
To delete a user:
- Log in to the product management console.
- On the Configure menu, click Users and Roles. The User Management page appears.
- Click Users. The Users page appears.
- Search for the user.
Click the Delete link respective to the user you wish to delete.
Click Yes, when the confirmation request appears.
You can not undo this operation once performed.
Changing my password
To change the current user's password:
- Log in to the product management console.
- On the Configure menu, click Users and Roles. The User Management page appears.
Click Change My Password. The Change Password page appears.
Enter the current password and the new password and click Change.
If the user has forgotten his/her current password, they need to contact the administrator and get their password reset.
Click OK, when the confirmation message appears.
Managing Roles
This following topics explain how user roles can be added and managed using the management console of your product.
Adding a user role
To add a user role:
- Log in to the product management console.
- On the Configure menu, click Users and Roles.
- Click Roles. The Roles page appears.
- Click Add New Role.
- Select the domain. By default, PRIMARY will appear to indicate the primary user store; however, if secondary user stores have been added they will be listed in the Domain drop-down list.
- Enter the name for the role.
- Click Next and proceed to the next step. You can also click Finish, in which case, the new roles will be created with default permissions (none) and no assigned users.
- Select permissions for the new role.
- Click Next.
- Enter a username pattern. Use one of the following approaches:
- Enter the exact username.
- Enter part of the username followed by or preceded by an asterisk (*) (for example, ad* - this option will return all the users that have usernames starting with "ad".)
- Enter only an asterisk (*). This option will return all the users under the selected domain.
- Select the users that will be assigned to the role.
- Click Finish.
The new role is added to the list on the Roles page.
When adding roles to external user stores
- Some external user stores do not allow you to create empty roles. In that case, selecting users who belong to a role is mandatory.
- If you connect to an external user store (e.g., LDAP) in the read only mode, you can read existing roles from it, but you can not edit/delete the roles. In this case, you can still create new roles that are editable and can be managed internally.
- If you connect to an external user store in read/write mode, you can edit the roles in the external user store as well.
Creating an internal role
- Log in to the product management console.
- On the Configure menu, click Users and Roles.
- Click Roles. The Roles page appears.
- Click Add New Internal Role.
- Enter a name for the role.
- Click Next to proceed to the next step. You can also click Finish, in which case, the new roles will be created with default permissions (none) and no assigned users.
- Select the respective permissions that need to be assigned to the role and click Next.
- Enter a username pattern and click Search.
- Enter the exact username.
- Enter part of the username followed by or preceded by an asterisk (*) (for example, ad* - this option will return all the users that have usernames starting with "ad".)
- Enter only an asterisk *. This option will return all the users that have not been assigned to this role.
- Select the respective users that need to be assigned to this role.
You can also click Finish. In this case, the new roles will be created with no assigned users. - Click Finish.
Searching for roles
To search for roles:
- Log in to the product management console.
- On the Configure menu, click Users and Roles.
- Click Roles. The Roles page appears.
- Select the user store domain.
- Enter a role name pattern. Use one of the following approaches:
- Enter the exact role name.
- Enter part of the role name followed by or preceded by an asterisk (*) (for example, t* - this option will return all the roles that have role names starting with "t".)
- Enter only an asterisk *. This option will return all the roles under the selected domain.
- Click Search.
Editing a user role
To edit a user role:
- Log in to the product management console.
- On the Configure menu, click Users and Roles.
- Click Roles. The Roles page appears.
- Search for the role.
- To Rename the role:
- Click Rename.
- Enter the new name of the role.
- Click Finish.
- To edit the permissions of the role:
- Click the respective Permissions link.
- Select/De-select on the permissions that you wish to add/remove.
- Click Update.
- A confirmation message appears. Click OK.
- To assign users to the role:
- Click the respective Assign Users link.
- Select on the users that you wish to assign to this role.
- Click Update.
- A confirmation message appears. Click OK.
- Click Finish.
Deleting a user role
To delete a user role:
- Log in to the product management console.
- On the Configure menu, click Users and Roles.
- Click Roles. The Roles page appears.
- Search for the role.
- Click the corresponding Delete link.
- Click Yes to accept the confirmation request.