Question
Anamata
NL
Last activity: 16 Oct 2018 12:03 EDT
Enable security policies by default
Is it possible to enable the security policies by default during or right after installation?
(without having it to manually enable it from the settings panel after logging in for the first time).
(pega 7.2.2 and/or pega 7.3 platform)
**Moderation Team has archived post**
This post has been archived for educational purposes. Contents and links will no longer be updated. If you have the same/similar question, please write a new post.
-
Like (0)
-
Share this page Facebook Twitter LinkedIn Email Copying... Copied!
JP Morgan
US
Are you referring to rule level security policy or container level?
Anamata
NL
The one set at "System > Settings > Security Policies > Enable Security Policies". I assume you call that container level.
JP Morgan
US
This setting is pretty much for a user with SysAdmin previlage to enable "captcha" on operators.
I don't see an option from server to enable captcha (tried with tomcat). The only way possible would be manually performing this change once in "Security Policies" once your instance is up.
Note: In cluster environments every tenant can have their own policy and if the user is shared the change will need 10 mins to reflect across instances.
Anamata
NL
I'm trying to automate as many configuration settings as possible. However, for now this (relative simple) setting still remains a challenge. ;-)
Anamata
NL
Anyone?
Pegasystems Inc.
US
Manually configured security policies are stored as data instance in database. may be you could update/import this record as part of the install or deployment(?).
Anamata
NL
That's a good suggestion. Will try and figure out where this value is stored in the DB. Thanks!
Pegasystems Inc.
US
looks like its stored under table 'pr_data_admin'.
select * From data.pr_data_admin where pxobjclass like 'Data-Admin-System-AuthPolicies';
RCDTS
GB
I'm new to this, so don't take this as gospel, but...
If you update the rule from the Designer Studio it saves rule Data-Admin-System-AuthPolicies.AuthenticationPolicies. You can see that rule under that class in the 'App' browser. It's got a system name associate (pega) and a production level.
You might want to exercise caution migrating this data instance, in case you lock yourself out.