On the Component List screen, select Options, then Add. Select the radio button for Use Existing Component. Select the NeedToKnow.hda file and click OK. Click Enable. Select the General Configuration link on the side bar in the Admin Server page. Under th
2. On the Component List screen, select Options, then Add.
The Appendix A.3.3.1, Add Component Screen displays.3. Select the radio button for Use Existing Component.
4. Browse to the location where the Enterprise Content Management ECM shiphome was installed and locate the Need to Know component directory. For example: ECM_HOME \ucm\cs\idc\components\NeedToKnow5. Select the NeedToKnow.hda file and click OK.
6. Click Enable.
The NTK component is listed as enabled. Installing the NTK component with ComponentTool: Run the Component Tool and specify the NeedToKnow.hda file with the following path, using your configuration name and path for ECM_HOME: ECM_HOME \ucm\cs\idc\components\NeedToKnow\NeedToKnow.hda B.3 Configuring the NTK Component This section describes the procedure to set up a basic security configuration using the Need to Know component. This procedure explains how to set up security configuration variables, a custom metadata field, and a hit list role. After you have set up the basic configuration, you can use the Need to Know component interface to edit, test, and improve the security configuration.1. Select the General Configuration link on the side bar in the Admin Server page.
2. Under the Additional Configuration Variables heading on the
Admin Server: General Configuration Page , scroll to the bottom of the text area, and add the following text: SpecialAuthGroups=group1,group2,... ■ Replace group1,group2,... with the security groups that will use the Need to Know component. ■ Security groups must be entered in lowercase letters. Note: You must open the Oracle Content Server Admin Server page for the applicable Oracle Content Server instance before starting the procedure. B-4 Oracle Fusion Middleware System Administrators Guide for Oracle Content Server ■ Any security groups not listed will have standard security applied. 3. If you want to specify content item-level queries, use the Configuration Manager to add a new metadata field. This is not necessary if you will be using only the global query. A new metadata field must be added by using the Configuration Manager; it cannot be added from the Need to Know component interface. ■ You can use any field name and title you wish, such as DocDisclosureQuery or NeedToKnow. ■ The field must be specified as a memo field. ■ After adding the field, you will need to click Update Database Design, and then click Rebuild Search Index. 4. Use the User Admin administration applet to add a hit list role. ■ You can use any role name you wish, such as hitlist or NTKrole. ■ Give Read access to all the security groups that were specified in the SpecialAuthGroups configuration entry. ■ If you want the security groups that were specified in the SpecialAuthGroups configuration entry to be listed on the check-in page or update page, you will need to give Write access to this role. ■ You can create two different hit list roles with different names and permissions. One role can be configured with the Need to Know component to be a Query role in a content search, and the other role can be configured with the Need to Know component to be an Update role in content check-ins and updates. ■ Do not assign this role to any users. If the hit list role is configured to be a Query or Update role, it is automatically added to the users attributes. 5. If you want to set user access permissions that extend the limits of Need to Know security, use the General Configuration page to include extra security configuration settings in the Additional Configuration Variables section. Scroll to the bottom of the text area and enter the configuration settings as necessary. 6. If you want to add new user attribute fields for use in Need to Know queries, use the User Admin tool to add user attribute fields. 7. Restart the Oracle Content Server instance. Note: Other products such as Universal Records Management also can use the SpecialAuthGroups configuration variable, so be careful to use unique names for security groups that use the Need to Know component. Note: If your Oracle Content Server instance already has a large amount of content, rebuilding the search index can take a long time up to a couple of days. Consider rebuilding during system maintenance periods or at times of non-peak system usage. Need to Know Component B-5 B.4 Using the NTK Component This section covers the following topics: ■ Appendix B.4.1, Security Configuration Customization ■ Appendix B.4.2, Disclosure Query Security Applet ■ Appendix B.4.3, Query Syntax ■ Appendix B.4.4, Defining a Content-Level Query ■ Appendix B.5.1, NTK Configuration Information Page B.4.1 Security Configuration Customization The Need to Know component provides additional security configuration support focused on the following areas: ■ Content Security : Changing user access to content items. ■ Search Results : Changing the display of search results. ■ Hit List Roles : Changing user credentials for query and check-in pages. ■ WHERE Clause Calculation : Changing use of the WHERE clause in searches. ■ Content Metadata Security : Changing the behavior of metadata changes for content items. B.4.1.1 Content Security Standard security uses security roles, groups, and accounts to determine if a user has the appropriate privilege level to access a content item. The Need to Know component enables you to customize the process of determining user privilege. You can use the Need to Know component interface to set configuration fields and create Idoc Script to specify Read, Write, and Delete privilege levels. The Idoc Script can also contain user and content metadata values. The Need to Know component computes content security using the following process:1. A user clicks a link to view content information.
Parts
» Oracle Fusion Middleware Online Documentation Library
» Understanding Oracle Universal Content Management and Oracle Content Server
» Utilities Management Pages Applications Command Line
» Administration Tray Admin Applets Page
» Modifying Server Configuration Parameters for Oracle Content Server
» Viewing Log Information for Oracle Content Server
» Starting Oracle Content Server with Scripts
» Restarting Oracle Content Server with Scripts
» Viewing MBean Information for Oracle Content Server Accessing Oracle Content Server With a Browser
» Click OK. Running a Standalone Application on a Windows System
» Delete Update About Batch Loading
» Optional Parameters About Batch Loading
» About Preparing a Batch Load File
» About Running the Batch Loader Batch Loading from the Command Line
» Using the IdcCommand Utility and Remote Access
» Example: Best Practice Case Study
» Log File Characteristics Accessing the Log Files
» Accessing the Content Server Analyzer Viewing the Analysis Progress and Results
» Configuration Information Environment Packager Configuration Debug Entry
» About System Properties Configuring System Properties
» Configuring Content Security Configuring Internet Information Configuring the Database
» About The Oracle Query Optimizer Component Query Optimization Process
» How Reformatted Queries Optimize Searches
» Types of Recognized Hints Query Hints Syntax
» Additional Supported Sort Constructs The Hint Rules Table Edit Hint Rules Form
» The Hint Cache Searching Content Using the Oracle Query Optimizer Component
» Enter the applicable information for the query and hints. Click Remove.
» Data Management Introduction to the File Store System
» DefaultFileStore Settings Empty Storage Rule
» Using Standard Oracle Content Server Variables
» Understanding FileStoreProvider Storage Principles
» PartitionList Table StorageRules Table
» PathMetaData Table PathConstruction Table
» FileSystemFileStoreAlgorithmFilters Table FileStoreProvider Resource Tables
» Example PathMetaData Table Options Configuration for Standard File Paths
» Configuration for a Webless or Optional Web Store
» Configuration for Database Storage Altered Path Construction and Algorithms
» Script Construction Mapping URLs with WebUrlMapPlugin
» Supported Variables for Referencing AddEdit URL Mapping Entries
» Info Update Form Dynamic Conversion CGI parameters
» Oracle Content Server Providers
» Choosing an Appropriate Provider
» Security Providers About Providers
» Changes in Security Compared to Oracle Content Server 10g
» Security within Oracle Content Server
» Additional Security Options Introduction to Oracle UCM and Oracle Content Server Security
» Configuring Oracle UCM for Two-Way SSL Communication
» Configuring Oracle Access Manager 11g with Oracle UCM
» Configuring Oracle Access Manager 10g with Oracle UCM
» Configuring Oracle Single Sign-On for Oracle UCM
» Configuring Oracle WebLogic Server Web Services
» External Users Introduction to User Login Types
» Local Users Introduction to User Login Types
» Introduction to User Logins and Aliases
» Highlight the alias to be deleted and click Delete.
» Best Practices for Working with Security Groups Performance Considerations
» Predefined Roles About Permissions
» Accounts and Security Groups Hierarchical Accounts
» Assigning Accounts to a User with Oracle WebLogic Server
» Xalco Security Xalco Accounts
» Xalco Roles Roles and Permissions Table Roles and Users Table Accounts and Users Table
» Empty Access Control List Fields
» About Proxy Connections Additional Oracle Content Server Security Connections
» About Credential Mapping Credential Values
» About Named Password Connections Guidelines for Proxy Connections Data
» About Using HTTP Protocol for Content Server Connection Configuring the HTTP Provider
» About BrowserUrlPath Customization Browser URL Customization
» Affected Idoc Script Variables and Functions
» Changing Absolute Full Path Computation Changing Administration Path Computation
» ExtUserAttribInfo ResultSet Extended User Attributes
» encodeHtml Function Filter Data Input
» HtmlDataInputFilterLevel Configuration Variable Filter Data Input
» Viewing Information about a Component
» Enabling and Disabling a Component Uploading a Component
» Select the Template option. The Click Next. Click Next.
» Click Select. To show the entire list of predefined templates, select Show All. Click OK.
» Click Select. Select a query from the list. Click OK.
» Click Select. To show the entire list of predefined services, select Show All. Click OK.
» Click Select. To show the entire list of predefined includes, select Show All. Click OK.
» Click Insert. Repeat these steps until all of the table columns have been Click OK.
» Considerations for Using OracleTextSearch Configuring OracleTextSearch for Oracle Content Server
» Indexing and Query Speeds and Techniques
» Fast Rebuild Query Syntax OracleTextSearch Operators
» Case Sensitivity and Stemming Rules Search Results Data Clustering
» Snippets Additional Changes Oracle Text 11g Features and Benefits
» Determining Fields to Optimize Modifying the Fields Displayed on Search Results
» Searching with OracleTextSearch Metadata Wildcards
» Search Results with OracleTextSearch
» Configuring an Oracle Content Server Source with Other Single Sign-On Solutions
» Configuration Migration Introduction to Migration Tools and Components
» Archiver Introduction to Migration Tools and Components
» Folder Archiving FolderStructureArchive Component
» Migration Structure About Migration Templates and Bundles
» Limitations Migration Logs Migration Tips
» Using a web browser, select Config Migration Admin from the Oracle Content
» Archive Structure Collections Archive Details
» If required, enter the administrator login name and password, then click OK. Enter .archive
» Click Update. Click Delete. Select Custom Query Expression.
» Update Import Rule Insert Revision Import Rule Insert Create Import Rule
» Transfer Uses Transfer Methods Transfer Terms
» Local Transfer Pull Transfer Push Transfer
» Transferring Batch Files Transferring Files
» Single Revision Replications Replication Uses
» Click Edit. Select Is Transfer Automated. Click OK.
» Export Import Self ExportImport
» One-to-One Archiving One-to-Many Archiving
» Adding Content ID Prefixes Changing Release Dates
» Many-to-One Archiving Configuration Migration Tips
» Overview of FolderStructureArchive Component Differences With Built-in Folders Archiving Features
» Using a Folder Structure Archive Configuration Variables
» Important Implementation Considerations Folder Structure Archiving
» How ArchiverReplicationExceptions Works Scenario 1 Scenario 2
» Administering and Using ArchiverReplicationExceptions
» Total Export Possible with Blank Export Query New Check-Ins and Batch File Transfers
» Folder Archive Export Doesnt Work If Collections Table Has Many Records
» Select an archive. Click the Click Edit in the Export Query section.
» Click the Select an archive from the Current Archives list Click the
» Click the Table list Edit button.
Show more