IBMDO YOU?Hi, I'm MBO!

Settings

Make the site feel at home on your screen.

Theme

Loading your theme preference.

Keyboard shortcuts

Open search from anywhere, then move through the results without leaving the keyboard.

Open settings
Ctrl,or⌘,
Open search
CtrlKor⌘K
Select a search result
↑↓
Open the selected result
Enter
Close an open dialog
Esc

I Build Maximo

Enable native web service security in Maximo

Require Maximo native authentication for enterprise, object structure, action and workflow services.

Before you begin: this procedure changes Maximo's deployment descriptor and requires you to rebuild and redeploy the application EAR. Back up the file, test the change outside production and make sure you have a rollback plan before replacing a deployed application.

Older Maximo installations that use native authentication may allow deployed web services to use a default login. You can disable that behaviour by changing ALLOWDFLTLOGIN in the EJB definitions used by Maximo's integration services.

This procedure was tested with Maximo 7.5.0.6. Later releases may generate or secure these services differently, so check the deployment descriptor and documentation supplied with your installation before applying it.

Back up the deployment descriptor

Stop before editing the file and take a copy of:

<install-root>\SMP\maximo\applications\maximo\mboejb\ejbmodule\META-INF\ejb-jar.xml

Open ejb-jar.xml in a text editor. The file contains four service definitions that need the same change:

Service Session ID EJB name
Enterprise Services Session_enterpriseservice enterpriseservice
Object Structure Services Session_mosservice mosservice
Action Services Session_actionservice actionservice
Workflow Services Session_wfservice wfservice

Use the session IDs to find the correct definitions. Do not replace every occurrence of ALLOWDFLTLOGIN without checking which EJB it belongs to.

Disable the default login

Each service definition contains this environment entry:

<env-entry>
  <env-entry-name>ALLOWDFLTLOGIN</env-entry-name>
  <env-entry-type>java.lang.String</env-entry-type>
  <env-entry-value>1</env-entry-value>
</env-entry>

Change the value from 1 to 0:

<env-entry>
  <env-entry-name>ALLOWDFLTLOGIN</env-entry-name>
  <env-entry-type>java.lang.String</env-entry-type>
  <env-entry-value>0</env-entry-value>
</env-entry>

Make this change inside all four session definitions listed above. Leave the surrounding EJB class, interface and security-role settings as they are.

For example, the updated Enterprise Services definition should contain:

<session id="Session_enterpriseservice">
  <ejb-name>enterpriseservice</ejb-name>
  <home>psdi.iface.gateway.MEAGatewayHome</home>
  <remote>psdi.iface.gateway.MEAGateway</remote>
  <local-home>psdi.iface.gateway.MEAGatewayHomeLocal</local-home>
  <local>psdi.iface.gateway.MEAGatewayLocal</local>
  <ejb-class>psdi.iface.gateway.MEAGatewayBean</ejb-class>
  <session-type>Stateless</session-type>
  <transaction-type>Container</transaction-type>
  <env-entry>
    <env-entry-name>ALLOWDFLTLOGIN</env-entry-name>
    <env-entry-type>java.lang.String</env-entry-type>
    <env-entry-value>0</env-entry-value>
  </env-entry>
  <security-role-ref>
    <description>MAXIMO Application Users</description>
    <role-name>maximouser</role-name>
    <role-link>maximouser</role-link>
  </security-role-ref>
</session>

The mosservice, actionservice and wfservice definitions keep their existing classes and interfaces; only their ALLOWDFLTLOGIN value changes.

Rebuild and redeploy Maximo

Save ejb-jar.xml, then use the build process supplied with your Maximo installation to rebuild the Maximo EAR. Redeploy the rebuilt EAR and redeploy the affected web, action and workflow services.

After the application starts, test each service with and without valid Maximo native credentials. A request without valid credentials should no longer be accepted through the default login path, while an authorised Maximo user should still be able to call the service.

Keep the backup until all four service types have been tested. If the application fails to start or an integration stops working unexpectedly, restore the original descriptor, rebuild the EAR and redeploy it.

Find the fix

Search articles

Esc

Search titles, technical terms or error codes.