Before you begin: this procedure changes Maximo's deployment descriptor and requires you to rebuild and redeploy the application EAR. Back up the file, test the change outside production and make sure you have a rollback plan before replacing a deployed application.
Older Maximo installations that use native authentication may allow deployed web services to use a default login. You can disable that behaviour by changing ALLOWDFLTLOGIN in the EJB definitions used by Maximo's integration services.
This procedure was tested with Maximo 7.5.0.6. Later releases may generate or secure these services differently, so check the deployment descriptor and documentation supplied with your installation before applying it.
Back up the deployment descriptor
Stop before editing the file and take a copy of:
<install-root>\SMP\maximo\applications\maximo\mboejb\ejbmodule\META-INF\ejb-jar.xmlOpen ejb-jar.xml in a text editor. The file contains four service definitions that need the same change:
| Service | Session ID | EJB name |
|---|---|---|
| Enterprise Services | Session_enterpriseservice |
enterpriseservice |
| Object Structure Services | Session_mosservice |
mosservice |
| Action Services | Session_actionservice |
actionservice |
| Workflow Services | Session_wfservice |
wfservice |
Use the session IDs to find the correct definitions. Do not replace every occurrence of ALLOWDFLTLOGIN without checking which EJB it belongs to.
Disable the default login
Each service definition contains this environment entry:
<env-entry>
<env-entry-name>ALLOWDFLTLOGIN</env-entry-name>
<env-entry-type>java.lang.String</env-entry-type>
<env-entry-value>1</env-entry-value>
</env-entry>Change the value from 1 to 0:
<env-entry>
<env-entry-name>ALLOWDFLTLOGIN</env-entry-name>
<env-entry-type>java.lang.String</env-entry-type>
<env-entry-value>0</env-entry-value>
</env-entry>Make this change inside all four session definitions listed above. Leave the surrounding EJB class, interface and security-role settings as they are.
For example, the updated Enterprise Services definition should contain:
<session id="Session_enterpriseservice">
<ejb-name>enterpriseservice</ejb-name>
<home>psdi.iface.gateway.MEAGatewayHome</home>
<remote>psdi.iface.gateway.MEAGateway</remote>
<local-home>psdi.iface.gateway.MEAGatewayHomeLocal</local-home>
<local>psdi.iface.gateway.MEAGatewayLocal</local>
<ejb-class>psdi.iface.gateway.MEAGatewayBean</ejb-class>
<session-type>Stateless</session-type>
<transaction-type>Container</transaction-type>
<env-entry>
<env-entry-name>ALLOWDFLTLOGIN</env-entry-name>
<env-entry-type>java.lang.String</env-entry-type>
<env-entry-value>0</env-entry-value>
</env-entry>
<security-role-ref>
<description>MAXIMO Application Users</description>
<role-name>maximouser</role-name>
<role-link>maximouser</role-link>
</security-role-ref>
</session>The mosservice, actionservice and wfservice definitions keep their existing classes and interfaces; only their ALLOWDFLTLOGIN value changes.
Rebuild and redeploy Maximo
Save ejb-jar.xml, then use the build process supplied with your Maximo installation to rebuild the Maximo EAR. Redeploy the rebuilt EAR and redeploy the affected web, action and workflow services.
After the application starts, test each service with and without valid Maximo native credentials. A request without valid credentials should no longer be accepted through the default login path, while an authorised Maximo user should still be able to call the service.
Keep the backup until all four service types have been tested. If the application fails to start or an integration stops working unexpectedly, restore the original descriptor, rebuild the EAR and redeploy it.