Role Mapping (roles-map.xml) Configuration File

Use the <UnwiredPlatform_InstallDir>\SCC-XX\conf\roles-map.xml to map roles for Sybase Control Center.

The <uaf-roles> section of the configuration file defines the available Sybase Control Center logical roles. The syntax is:
<uaf-roles>
   <role name="<myRoleName>" description="<myRoleDescription>"
</uaf-roles>
The <security-modules> section lists each login module defined in csi.properties file and maps the security provider's physical roles to the logical roles for Sybase Control Center. Typically, Sybase recommends that you only use the Delegation Login Module and only map roles for this login :
<?xml version="1.0" encoding="UTF-8"?>
<roles-map>
 <uaf-roles>
   <role name="uaAgentAdmin" description="Agent administrator role" />
   <role name="uaPluginAdmin" description="Plugin administrator role" />
   <role name="uaOSAdmin" description="Operation system administrator role" />
   <role name="uaASEAdmin" description="ASE administrator role" />
   <role name="uaUser" description="User role" />
   <role name="uaGuest" description="Guest role" />
   <role name="uaAnonymous" description="Anonymous role" />
   <role name="sccAdminRole" description="SCC Administrator Role" />
   <role name="sccOperRole" description="SCC Operator Role" />
   <role name="sccUserRole" description="SCC User Role" />
   <role name="sccGuestRole" description="SCC Guest Role" />
   <role name="jmxDirectAccess" description="JMX Direct Access Role" />    
 </uaf-roles>
 <security-modules>

   <module name="SUP Delegation Login Module">
     <role-mapping modRole="SUP Administrator" uafRole="uaAnonymous,uaAgentAdmin,uaPluginAdmin,sccAdminRole,sccUserRole,sccOperRole,sccGuestRole,jmxDirectAccess"/>
     <role-mapping modRole="SUP Domain Administrator" uafRole="uaAnonymous,uaAgentAdmin,uaPluginAdmin,sccUserRole,sccOperRole,sccGuestRole,jmxDirectAccess"/>
   </module>
   <module name="Anonymous Login Module">
     <role-mapping modRole="uaAnonymous" uafRole="uaAnonymous" />
   </module>
 </security-modules>
</roles-map>

If necessary, replace the modRole values for each applicable login module with your own security provider role names to map them to Sybase Control Center roles. By default, the configuration file assumes that the security repository includes the "SUP Administrator" and "SUP Domain Administrator" roles. The "SUP Domain Administrator" role mapping is required only if you plan to assign domain administrators within the cluster.