03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring Client01<br />

Client01 requires message layer authentication with an SSL transport. follow the<br />

steps below to configure Client01.<br />

1. The client needs to point to the sas.client.props file using the property<br />

com.ibm.CORBA.ConfigURL=file:/c:/websphere/appclient/properties/sas.<br />

client.props.<br />

2. All further configuration involves setting properties within the sas.client.props<br />

file, open it in a text editor in the /properties<br />

directory.<br />

3. Enable SSL for the connection, in this case, SSL will be supported but not<br />

required: com.ibm.CSI.performTransportAssocSSLTLSSupported=true,<br />

com.ibm.CSI.performTransportAssocSSLTLSRequired=false.<br />

4. Enable client authentication at the message layer. In this case, client<br />

authentication is supported but not required:<br />

com.ibm.CSI.performClientAuthenticationRequired=false,<br />

com.ibm.CSI.performClientAuthenticationSupported=true.<br />

5. Save the file then close it.<br />

Configuring Server01<br />

In the Administrative console, Server01 will be configured for incoming requests<br />

to support message layer client authentication and incoming connections to<br />

support SSL without client certificate authentication. Server01 will be configured<br />

for outgoing requests to support identity assertion. Follow the steps below to<br />

configure Server01:<br />

1. Configure Server01 for incoming connections. Start the Administrative<br />

Console for Server01, then navigate to the <strong>Security</strong> -> Authentication<br />

Protocol section.<br />

a. Select CSIv2 Inbound Authentication.<br />

i. Enable Basic Authentication by selecting Supported.<br />

ii. Disable Client Certificate Authentication by selecting Never.<br />

iii. Disable Identity Assertion.<br />

b. Select CSIv2 Inbound Transport.<br />

Enable SSL by selecting SSL-Supported.<br />

2. Configure Server01 for outgoing connections.<br />

a. Select CSIv2 Outbound Authentication.<br />

i. Enable Basic Authentication by selecting Supported.<br />

ii. Disable Identity Assertion.<br />

118 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!