(V5.5.1 and later only) Creating Content Platform Engine System User account

The cpe_system_user provides credentials used in a subset of tasks that are run by the services provided with the FileNetEngine application.

About this task

If you are using V5.5.0, this user does not apply. The System User account is used in V5.5.1 and later.

Procedure

  1. Create the following LDAP account:
    Content Platform Engine System User account
    Unique identifier
    cpe_system_user
    Description
    The cpe_system_user is a user account that has Full Control access rights to the FileNet® P8 domain, and has also been granted rights through its membership in the object store. The cpe_system_user provides credentials used in a subset of tasks that are run by the services provided with the FileNetEngine application.

    Use the IBM® Administration Console for Content Platform Engine to add the cpe_system_user account, or the directory server group containing the cpe_system_user, to the security of the FileNet P8 domain object, making sure to grant Full Control to the P8 domain.

    Additionally the cpe_system_user should also be part of the group assigned as the workflow_system_admin to use for workflow system processing. Content Platform Engine permissions can be granted by a gcd_admin who uses IBM Administration Console for Content Platform Engine to add the workflow_system_admin to the ACL of the FileNet P8 domain and grant it Full Control. The workflow_system_admin therefore has permissions equivalent to the gcd_admin but should be used only for workflow purposes.

    The cpe_system_user credentials are stored in the Global Configuration Database (GCD) and can be updated through the IBM Administration Console for Content Platform Engine. Updating these credentials in the administration console should take the following into consideration:
    • Takes a maximum of only ten minutes to propagate the credentials update to all servers in a cluster.
    • No restart of the Content Platform Engine server is needed.
    Restriction: If you are deploying Content Platform Engine on an application server with federated user repositories and with multiple realms in your FileNet® P8 domain, be sure that no two realms contain the same short name for this user; otherwise, this user will not be able to authenticate.
    Minimum required permissions
    The account must be a directory server account that resides in the realm that has been configured for Content Platform Engine authentication.
    An exception to this rule is that if you are using IBM virtual member manager, the bootstrap account must reside in the file-based repository if your repository is file-based, or in the custom repository if your repository is a custom repository.
    If you are using WebSphere® Application Server security domains, see Security planning considerations for additional requirements for cpe_system_user.
  2. Icon representing the worksheet Record this value in your customized Installation and Upgrade Worksheet. To find this property, search the worksheet for instances of cpe_bootstrap_admin.