03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

The sas.client.props file<br />

The CORBA authentication options (with the valid values / default value in<br />

brackets) in the client property file are listed below.<br />

►<br />

►<br />

►<br />

►<br />

com.ibm.CORBA.securityEnabled (true, false / true) - determines if client<br />

security has been enabled<br />

com.ibm.CSI.protocol (ibm, csiv2, both / both) - determines which<br />

authentication protocol the client is permitted to use<br />

com.ibm.CORBA.authenticationTarget (BasicAuth) - determines the type of<br />

authentication mechanism to use. The user name and password will be<br />

communicated to the server. In this case, SSL should be enabled in order to<br />

encrypt this information.<br />

com.ibm.CORBA.validateBasicAuth (true, false / true) - determines if the user<br />

details are authenticated immediately or deferred until the first method<br />

request is communicated to the server. Requires the<br />

com.ibm.CORBA.authenticationTarget property to be set to BasicAuth.<br />

► com.ibm.CORBA.authenticationRetryEnabled (true, false / true) - determines<br />

whether a failed login should be retried. This also applies to stateful CSIv2<br />

sessions and validations that have failed due to an expired credential. Only<br />

those failures which are known to be correctable will be retried.<br />

► com.ibm.CORBA.authenticationRetryCount (an integer within the range 1<br />

and 10 / 3) - determines how many retries will be attempted. Requires<br />

com.ibm.CORBA.authenticationRetryEnabled to be set to true.<br />

► com.ibm.CORBA.loginSource (prompt, key file, stdin, none, properties /<br />

prompt) - determines how the authentication request interceptor will log in if it<br />

does not find a invocation credential set. Requires<br />

com.ibm.CORBA.loginUserid and com.ibm.CORBA.loginPassword<br />

properties to be set. The prompt will display a window requesting a user<br />

name and password, the key file will extract the user details from the file<br />

specified by com.ibm.CORBA.keyFileName, stdin will display a command line<br />

prompt requesting user details, none should be selected only if the client<br />

uses programmatic login (see Chapter 8, “Programmatic security” on<br />

page 179) and properties will retrieve the user details from the<br />

com.ibm.CORBA.loginUserid and com.ibm.CORBA.loginPassword<br />

properties.<br />

►<br />

►<br />

com.ibm.CORBA.loginUserid (user ID / blank) - determines the user ID when<br />

the com.ibm.CORBA.loginSource property is set to properties. Requires<br />

com.ibm.CORBA.loginPassword property to be set and CSIv2 message layer<br />

authentication in use.<br />

com.ibm.CORBA.loginPassword (password / blank) - determines the user<br />

password when the com.ibm.CORBA.loginSource property is set to<br />

104 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!