Click OK. Click Delete. Click Selected Roles. Click Add.

11-66 Oracle Fusion Middleware Security and Administrators Guide for Web Services http:java.sun.comj2se1.5.0docsapijavasecurityPermission .html . The default is oracle.wsm.security.WSFunctionPermission. How to Set Up Oracle Platform Security Services OPSS Use Fusion Middleware Control to grant the WSFunctionPermission or other permission to the user, group, or application that will attempt to authenticate to the Web service. You have the option to change the permission_class configuration property for the policy, which identifies the permission class as per JAAS standards. The class must be available in the server classpath. The default is oracle.wsm.security.WSFunctionPermission. You must configure a WebLogic Authentication provider, as described in Configure Authentication and Identity Assertion providers in the Oracle WebLogic Server Administration Console Help. oraclecomponent_authorization_denyall_policy This policy provides a simple role-based authorization policy based on the authenticated subject. This policy denies all users with any roles. You must have already configured a WebLogic Authentication provider, as described in Configure Authentication and Identity Assertion providers in the Oracle WebLogic Server Administration Console Help. This policy should follow an authentication policy where the subject is established and can be attached to any SCA-based endpoint. This policy contains the following assertion template: oraclecomponent_ authorization_template. See oraclecomponent_authorization_template on page C-91 for more information about the assertion. Settings You Can Change See Table C–88 . To add roles:

1. Click Add.

2. To add roles, click the check box next to each role you want to add in the Roles Available column and click Move. To add all roles, click Move All. To remove roles, click the check box next to each role you want to remove in the Roles Selected to Add column, and click Remove. To remove all roles, click Remove All . To search for roles, enter a search string in the Role Name search box and click the go arrow. The Roles Available column is updated to include only those roles that match the search string.

3. Click OK.

To delete roles: 1. Select the role that you want to delete in the Selected Roles list.

2. Click Delete.

Configuring Policies 11-67 Properties You Can Configure None defined. How to Set Up Oracle Platform Security Services OPSS If you specify one or more of the WebLogic Server enterprise roles, the authenticated subject must already have that role. You use the WebLogic Server Administration Console to grant a role to a user or group, as described in the Oracle WebLogic Server Administration Console Help. You must configure a WebLogic Authentication provider, as described in Configure Authentication and Identity Assertion providers in the Oracle WebLogic Server Administration Console Help. oraclecomponent_authorization_permitall_policy This policy provides a simple role-based authorization policy based on the authenticated subject. This policy permits all users with any roles. You must have already configured a WebLogic Authentication provider, as described in Configure Authentication and Identity Assertion providers in the Oracle WebLogic Server Administration Console Help. It should follow an authentication policy where the subject is established and can be attached to any SCA-based endpoint. This policy contains the following assertion template: oraclecomponent_ authorization_template. See oraclecomponent_authorization_template on page C-91 for more information about the assertion. Settings You Can Change See Table C–88 . To add roles:

1. Click Add.

2. To add roles, click the check box next to each role you want to add in the Roles Available column and click Move. To add all roles, click Move All. To remove roles, click the check box next to each role you want to remove in the Roles Selected to Add column, and click Remove. To remove all roles, click Remove All . To search for roles, enter a search string in the Role Name search box and click the go arrow. The Roles Available column is updated to include only those roles that match the search string.

3. Click OK.