03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The CSIv2 configuration properties are listed below. Certain security properties<br />

have supported/required property pairs. If the required property is enabled then<br />

communication with the server must satisfy this property.<br />

►<br />

►<br />

►<br />

►<br />

►<br />

►<br />

com.ibm.CSI.performStateful (true, false / true) - determines whether the<br />

authentication request should result in a stateful reply returning from the<br />

server.<br />

com.ibm.CSI.performTLClientAuthenticationRequired (true, false / false) and<br />

com.ibm.CSI.performTLClientAuthenticationSupported (true, false / false) -<br />

determines if transport-layer client authentication is required or supported.<br />

This will involve the client sending a digital certificate to the server during the<br />

authentication stage. If the Required property is set to true, the client will only<br />

authenticate with servers that support transport-layer client authentication.<br />

com.ibm.CSI.performTransportAssocSSLTLSRequired (true, false / false)<br />

and com.ibm.CSI.performTransportAssocSSLTLSSupported (true, false /<br />

true) - determines if the client can use SSL to communicate with the server. If<br />

the Required property is set to true, the client will only communicate with<br />

servers that support SSL.<br />

com.ibm.CSI.performClientAuthenticationRequired (true, false / true) and<br />

com.ibm.CSI.performClientAuthenticationSupported (true, false / true) -<br />

determines if message layer client authentication is required or supported.<br />

The com.ibm.CORBA.authenticationTarget property determines the type of<br />

authentication mechanism.<br />

com.ibm.CSI.performMessageIntegrityRequired (true, false / true) and<br />

com.ibm.CSI.performMessageIntegritySupported (true, false / true) -<br />

determines if a connection secured by a 40-bit cipher is supported or<br />

required. If the Required property is set to true then the connection will fail if<br />

the server does not support 40-bit ciphers. This property is only valid when<br />

SSL is enabled.<br />

com.ibm.CSI.performMessageConfidentialityRequired (true, false / false) and<br />

com.ibm.CSI.performMessageConfidentialitySupported (true, false / true) -<br />

determines if a connection secured by a 128-bit cipher is supported or<br />

required. If the Required property is set to true then the connection will fail if<br />

the server does not support 128-bit ciphers. This property is only valid when<br />

SSL is enabled.<br />

For a more complete list of directives, refer to the <strong>WebSphere</strong> Application Server<br />

InfoCenter for more details.<br />

The Application Server should also be configured to communicate with a client in<br />

the required fashion. If a Java client requires that client certificates be transmitted<br />

via SSL, for example, then the server must be set to expect this. Details on the<br />

configuration of the Application Server can be found in Chapter 10,<br />

“Administering <strong>WebSphere</strong> security” on page 233.<br />

106 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!