03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

2. Save the configuration for <strong>WebSphere</strong> to have the generated keys stored in<br />

the <strong>WebSphere</strong> configuration; they will appear in the security.xml file.<br />

3. Re-open the LTPA configuration page.<br />

4. Specify the Key File Name which is the name of the file where LTPA keys will<br />

be stored when you export them. You need to export the keys in order to<br />

enable Single Sign-On on another server. Specify the full path name for the<br />

key file. We have used c:\<strong>WebSphere</strong>\Appserver\etc\SSO_ltpakeys.<br />

5. Click Export Keys. Keys that have been exported in our scenario are<br />

presented in the example below.<br />

Example 10-1 Contents of the key file generated from <strong>WebSphere</strong> LTPA panel<br />

#<strong>IBM</strong> <strong>WebSphere</strong> Application Server key file<br />

#Tue Aug 13 18:25:07 EDT 2002<br />

com.ibm.websphere.CreationDate=Tue Aug 13 18\:25\:07 EDT 2002<br />

com.ibm.websphere.ltpa.version=1.0<br />

com.ibm.websphere.ltpa.3DESKey=FDspFou4xxe1m4Il84JmAk+EXLb1QclZp7ji+BJPSDM\=<br />

com.ibm.websphere.CreationHost=wassrv01<br />

com.ibm.websphere.ltpa.PrivateKey=9qo7ytSCbTf/62bvAyExobRikGAwF4vE/vKnKe7K80eJa<br />

/jUoiAtyeo6rQumiUw/otwCBSaGWWvAHAwpTKR3CP7oJm4CAxyj0UVNF2B2iSZspH+ekZ+fS62Amp64<br />

HT+ppljshfmyjX4WZAOxRQdKpvHvX3BUMU1BjuRnlpQqp2Pov/VlBqpnSJI5vcLRrXZDCNUEA4Kd0CH<br />

cKyq5H22Iox4PiZ4rvpZ5UCXdjxfcA0rUbw+5KK1eZdVQLrcxHb/ufBQ51RrA6m2R8PCZua26RUOJwi<br />

x1Y0JpGBuwKNeKDCq/pY4l70K4nkyOEXrq7EBl0VkhtC7JEsR4o5Mbc1JSbuyCJsRamjgX5/plEFZSB<br />

HE\=<br />

com.ibm.websphere.ltpa.Realm=dirsrv01.itso.ibm.com\:389<br />

com.ibm.websphere.ltpa.PublicKey=AO/uOSd3vL4zo7VUN3k8VSw9F+zpgwbRnDHmi8G8gmm5Tb<br />

CKGonK4Hl+gQ9dzSDNgkDJ3BWYJEkrCj77oZsI4RCZZk1RexDqLByEO9ffR/WyT7PR4FaMMFaZo0Iha<br />

DX3GyF3yHov6l3/DcsrvYCLgO3Fc+SPsX/QnHPDQOXyKZ6lAQAB<br />

As you can see in the example, three types of keys have been generated for<br />

LTPA.<br />

► The private key, used for the LTPA server to sign the LTPA token.<br />

► The public key, used to verify the digital signature.<br />

► A shared key, used to encrypt/decrypt those tokens.<br />

10.6.4 Enabling LTPA authentication for <strong>WebSphere</strong><br />

The following steps will show you how to enable LTPA for <strong>WebSphere</strong><br />

Application Server.<br />

1. Select <strong>Security</strong> -> Global <strong>Security</strong> in the Administrative Console.<br />

2. Make sure that Active Authentication Mechanism is set to LTPA (Light weight<br />

Third Party Authentication).<br />

254 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!