...
After the UCD code is in place, follow these steps to add SU access and to provide users with that access:
- Access Realms and select New Realm. Enter and save the following settings:
- Realm Id: !su.can_su_realm
- Provider Id: null - leave blank
- Maintain Role: maintain
- Select the newly created realm and then select Add Role. Enter a name and short description which will make sense to others.
Set Should this role be limited to the group provider only? to No and check su.can_su as the function, and save. - Select Grant Ability. Enter a user's Kerberos name in User Id and select the role that you created in the last step.
Provide each user with access to the Become User function: