Security Management Configuration

Overview

You can configure security management in Bloomreach Content using global settings and by integrating with external security providers such as LDAP.

Configuration Storage Location

Security management configuration is stored under the following node, which uses the hipposys:securityfolder node type:

/hippo:configuration/hippo:security

Node Type hipposys:securityfolder

[hipposys:securityfolder] > nt:base
- hipposys:userspath (string) // obsolete, no longer user
- hipposys:groupspath (string) // obsolete, no longer used
- hipposys:rolespath (string) // obsolete, no longer used
- hipposys:domainspath (string) // obsolete, no longer used
- hipposys:passwordmaxagedays (double) // obsolete, use the property with type long instead 
- hipposys:passwordmaxagedays (long)
+ hipposys:accessmanager (hipposys:accessmanager) = hipposys:accessmanager
+ * (hipposys:securityprovider) = hipposys:securityprovider

The configuration properties for users, groups, roles, and domains storage paths are obsolete as of XM version 14. These paths are now fixed and cannot be changed. Store users, groups, roles, user roles, and domains at the following locations:

  • /hippo:configuration/hippo:users

  • /hippo:configuration/hippo:groups

  • /hippo:configuration/hippo:roles

  • /hippo:configuration/hippo:userroles

  • /hippo:configuration/hippo:domains

Use the hipposys:passwordmaxagedays property to set the number of days before a user password expires after its last modification. By default, passwords do not expire automatically. This property only applies to internal and non-system users.

The following sections describe how to configure the access manager and security providers.

Access Manager Configuration

The access manager configuration is stored as a child node of type hipposys:accessmanager at:

/hippo:configuration/hippo:security/hipposys:accessmanager

Node Typehipposys:accessmanager

[hipposys:accessmanager] > nt:base
- hipposys:permissioncachesize (long) = '20000' mandatory autocreated

Permission Cache

The access manager maintains a user-based cache for read access permissions. This cache tracks which nodes a user can or cannot read. Write permissions are always checked at runtime and are not cached. The cache size is defined as the number of items (nodes or properties) per user. Configure the cache size using the hipposys:permissioncachesize property.

Security Providers

The default internal security provider, and any additional custom security providers, are configured as child nodes of type hipposys:securityprovider:

/hippo:configuration/hippo:security/internal

A security provider can also supply a custom user provider and group provider. For example, the LDAP security provider synchronizes users and groups with the repository.

Node Type hipposys:securityprovider

[hipposys:securityprovider] > nt:base orderable
- hipposys:classname (string) mandatory
+ hipposys:userprovider (hipposys:userprovider) = hipposys:userprovider
+ hipposys:groupprovider (hipposys:groupprovider) = hipposys:groupprovider
+ hipposys:roleprovider (hipposys:roleprovider) = hipposys:roleprovider 

Node Type hipposys:userprovider

[hipposys:userprovider] >  nt:base
- hipposys:dirlevels (long) = '0' autocreated

Node Type hipposys:groupprovider

[hipposys:groupprovider] >  nt:base
- hipposys:dirlevels (long) = '0' autocreated

Directory Levels (hipposys:dirlevels)

hipposys:dirlevels controls how deeply new users and groups are nested into
sub-folders under /hippo:configuration/hippo:users and
/hippo:configuration/hippo:groups. The default value 0 stores every user
and group as a direct child of the root folder.

With a value of N, the first N characters of the (lowercased) user or group
name each become one folder level. Intermediate folders of type
hipposys:userfolder / hipposys:groupfolder are created automatically. If the
name is shorter than N, its last character is repeated for the remaining levels.

dirlevelsNameResulting path
0jdoe/hippo:configuration/hippo:users/jdoe
1jdoe/hippo:configuration/hippo:users/j/jdoe
2jdoe/hippo:configuration/hippo:users/j/d/jdoe
2a/hippo:configuration/hippo:users/a/a/a

Sharding is recommended when managing a large number of users or groups (for
example, more than one hundred), because it keeps the number of child nodes per
folder manageable.

Warning: hipposys:dirlevels is also used to locate existing users and
groups. Lookup resolves a user or group by the path derived from the
configured number of levels; it does not search for the node by name.
Changing the value on a repository that already contains users or groups
leaves those nodes where they are and makes them unresolvable at their old
location, which includes failing authentication. Set hipposys:dirlevels
during project setup, before any users or groups are created. To change it
afterwards, move the existing user and group nodes to match the new layout.

Note: As of version 17.3, users and groups created through Setup >
Users
and Setup > Groups in the CMS also honor this setting. In earlier
versions the CMS always created them directly under the root folder, and
hipposys:dirlevels applied only to externally synchronized users and groups
(for example through the LDAP add-on).

Share Feedback
Page: /about/for-architects/security-architecture/security-management-configuration
Section: About
Category *
Security Management Configuration | Bloomreach Content Documentation