(V5.5.1 and later only) Creating Content Platform Engine System User account
The cpe_system_user provides credentials used in a subset of tasks that are run by the services provided with the FileNetEngine application.
About this task
Procedure
-
Create the following LDAP account:
- Content Platform Engine System User account
-
- Unique identifier
- cpe_system_user
- Description
- The cpe_system_user is a user account that has Full Control access rights to
the FileNet® P8 domain, and has also been granted rights through its membership in the object store.
The cpe_system_user provides credentials used in a subset of tasks that are run
by the services provided with the FileNetEngine application.
Use the IBM® Administration Console for Content Platform Engine to add the cpe_system_user account, or the directory server group containing the cpe_system_user, to the security of the FileNet P8 domain object, making sure to grant Full Control to the P8 domain.
Additionally the cpe_system_user should also be part of the group assigned as the workflow_system_admin to use for workflow system processing. Content Platform Engine permissions can be granted by a gcd_admin who uses IBM Administration Console for Content Platform Engine to add the workflow_system_admin to the ACL of the FileNet P8 domain and grant it Full Control. The workflow_system_admin therefore has permissions equivalent to the gcd_admin but should be used only for workflow purposes.
The cpe_system_user credentials are stored in the Global Configuration Database (GCD) and can be updated through the IBM Administration Console for Content Platform Engine. Updating these credentials in the administration console should take the following into consideration:- Takes a maximum of only ten minutes to propagate the credentials update to all servers in a cluster.
- No restart of the Content Platform Engine server is needed.
Restriction: If you are deploying Content Platform Engine on an application server with federated user repositories and with multiple realms in your FileNet® P8 domain, be sure that no two realms contain the same short name for this user; otherwise, this user will not be able to authenticate. - Minimum required permissions
- The account must be a directory server account that resides in the realm that has been configured for Content Platform Engine authentication.
- An exception to this rule is that if you are using IBM virtual member manager, the bootstrap account must reside in the file-based repository if your repository is file-based, or in the custom repository if your repository is a custom repository.
- If you are using WebSphere® Application
Server security domains, see
Security planning considerations
for additional requirements for cpe_system_user.
-
Record this value in your customized Installation and Upgrade Worksheet. To
find this property, search the worksheet for instances of
cpe_bootstrap_admin.