Configuring CAS Resource Access Control (CRAC)

About this task

Using CRAC API Custom Resource (CR), you can define users and groups that can have access to the domain.

To configure CAS to restrict specific users to specific CAS domains, perform the following steps:

Procedure

  1. Open the IBM Fusion UI.
  2. Go to Content-aware Storage > Domains.
  3. Click the domain name that you want to open.
  4. Click Actions and select Share search access. The Share search access dialog opens.

  5. In the Username or Group field, add the username or group name to which you want to grant the domain access.
  6. From the Choose type dropdown, select the type as User or Group.
    Tip: To add all users or groups at the same time, click Add.
  7. Click Share.
    Note: When IDP CR is configured on your system, you can provide the external IDP token to the query search API for semantic search execution.

Removing search access

About this task

You can remove users and groups that have access to specific domains.

To remove users or groups from specific CAS domains, perform the following steps:

Procedure

  1. Open the IBM Fusion UI.
  2. Go to Content-aware Storage > Domains.
  3. Click the domain name that you want to open.
  4. Click Actions and select Remove search access. The Remove search access dialog opens.
  5. Select the users or groups whose search access is to be removed.
  6. Click Remove.

Results

Removed users and groups lose authorization to access the query search API for the domain.