Information about users and groups reside in a user registry.
WebSphere Application Server provides several implementations to support multiple types of operating system base user registries. You can use the custom LDAP feature to support any LDAP server by setting up the correct configuration (user and group filters). However, support is not extended to these custom LDAP servers because there are many configuration possibilities.
In addition to Local operating system (OS) and LDAP registries, WebSphere Application Server also provides a plug-in that supports any registry by using the custom registry feature (also referred to as a custom user registry). The custom registry feature supports any user registry that is not implemented by WebSphere Application Server. You can use any registry used in the product environment by implementing the UserRegistry interface interface.
The UserRegistry interface is very helpful in situations where the current user and group information exists in some other format (for example, a database) and cannot move to Local OS or LDAP. In such a case, implement the UserRegistry interface so that WebSphere Application Server can use the existing registry for all of the security-related operations. Using a custom registry is a software implementation effort, it is expected that the implementation does not depend on other WebSphere Application Server resources, for example, data sources, for its operation.
Although WebSphere Application Server supports different types of user registries, only one user registry can be active. This active registry is shared by all of the product server processes. If the product processes in one node or cell need to communicate with other product processes in other nodes or cells using Lightweight Third Party Authentication (LTPA), all of the nodes and cells share the same user registry.
Note: