03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring Server02<br />

In the Web Console, Server02 will be configured for incoming requests to<br />

support message layer authentication over SSL. Configuration for outgoing<br />

requests is not relevant for this scenario. Follow the steps below to configure<br />

Server02:<br />

1. Configure Server02 for incoming connections. Start the Administrative<br />

Console for Server02, then navigate to the <strong>Security</strong> -> Authentication<br />

Protocol section.<br />

2. Select CSIv2 Outbound Authentication.<br />

a. Enable Basic authentication, by selecting Supported.<br />

b. Disable Client Certificate Authentication by selecting Never.<br />

c. Disable Identity Assertion.<br />

3. Select CSIv2 Outbound Transport.<br />

Enable SSL by selecting SSL-Supported.<br />

Scenario 4: TCP/IP Transport using VPN<br />

This scenario illustrates the ability to choose TCP/IP as the transport when it is<br />

appropriate to do so. In some cases, when two servers are on the same VPN, it<br />

may be appropriate to select TCP/IP as the transport for performance reasons<br />

since the VPN already encrypts the message.<br />

invocation<br />

credential:<br />

user01<br />

VPN<br />

received<br />

credential:<br />

user01<br />

J<br />

user01/userpwd<br />

message layer<br />

SSL<br />

transport layer<br />

token<br />

message layer<br />

TCP/IP<br />

transport layer<br />

Client01<br />

Java client<br />

Server01<br />

EJB server<br />

Server02<br />

EJB server<br />

Figure 6-7 Scenario 4: TCP/IP Transport using VPN<br />

Chapter 6. Securing Java clients 117

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!