03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

3. Enable SSL for the connection, in this case, SSL will be supported but not<br />

required: com.ibm.CSI.performTransportAssocSSLTLSSupported=true,<br />

com.ibm.CSI.performTransportAssocSSLTLSRequired=false.<br />

4. Disable client authentication at the message layer.<br />

com.ibm.CSI.performClientAuthenticationRequired=false,<br />

com.ibm.CSI.performClientAuthenticationSupported=false.<br />

5. Enable client authentication at the transport layer. Here we are supporting it<br />

and not requiring it:<br />

com.ibm.CSI.performTLClientAuthenticationRequired=false,<br />

com.ibm.CSI.performTLClientAuthenticationSupported=true.<br />

6. Save the file then close it.<br />

Configuring Server01<br />

In the Web Console, Server01 will be configured for incoming connections to<br />

support SSL with client certificate authentication. Server01 will be configured for<br />

outgoing requests to support message layer client authentication. Follow the<br />

steps below to configure Server01:<br />

1. Configure Server01 for incoming connections. Start the Administrative<br />

Console for Server01, then navigate to the <strong>Security</strong> -> Authentication<br />

Protocol section.<br />

a. Select CSIv2 Inbound Authentication.<br />

i. Disable Basic Authentication, by selecting Never.<br />

ii. Enable Client Certificate Authentication by selecting Supported.<br />

iii. Disable Identity Assertion.<br />

b. Select CSIv2 Inbound Transport.<br />

Enable SSL by selecting SSL-Supported.<br />

2. Configure Server01 for outgoing connections.<br />

a. Select CSIv2 Outbound Authentication.<br />

i. Disable Basic Authentication by selecting Never.<br />

ii. Enable Client Certificate Authentication by selecting Supported.<br />

iii. Disable Identity Assertion.<br />

b. Select CSIv2 Outbound Transport.<br />

Enable SSL by selecting SSL-Supported.<br />

116 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!