03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

A Web browser, for instance, must be capable of sending HTTP requests in a<br />

secure fashion since this data may travel over an insecure connection to the<br />

server, that is, a connection sensitive to eavesdropping or other interference. The<br />

server, upon receiving a request, must be able to summon the appropriate<br />

resources in order to respond without revealing information unnecessarily to<br />

either the resource or a third party.<br />

As a request passes from one component to another, the opportunities for the<br />

interception and exposure of information increase and ultimately the overall<br />

security of a system directly relates to the weakest, or least secure, point.<br />

<strong>WebSphere</strong>, and indeed J2EE, do not implicitly provide a secure means of<br />

communication but rather rely on an additional service, typically a transport-layer<br />

digital encryption algorithm, called Secure Sockets Layer (SSL) and Transport<br />

Layer <strong>Security</strong> (TLS). This section describes how to configure <strong>WebSphere</strong> to use<br />

SSL to protect information as it is communicated from the client to the server and<br />

back.<br />

<strong>Security</strong> administration<br />

The <strong>Security</strong> section is the focal point for the configuration of <strong>WebSphere</strong><br />

security. It is accessible from the Admin Console. After logging in, click the<br />

<strong>Security</strong> link in the navigation pane.<br />

<strong>WebSphere</strong> security can be enabled and disabled in its entirety by selecting a<br />

single switch. This is the Global <strong>Security</strong> Enabled switch which is accessible from<br />

the Administrative Console under <strong>Security</strong> -> Global <strong>Security</strong>.<br />

236 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!