03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

15.Select Basic Settings -> Module Sequence. This presents a list of modules<br />

loaded by the <strong>IBM</strong> HTTP Server and should include the <strong>IBM</strong> <strong>WebSphere</strong><br />

AppServer module, which is probably at the top of the list. It is necessary to<br />

add the <strong>IBM</strong> SSL module.<br />

16.Click Add.<br />

17.From the Select a module to add drop-down list, select<br />

ibm_ssl(<strong>IBM</strong>ModuleSSL128.dll).<br />

18.Ensure that the Module dynamic link library is set to<br />

modules/<strong>IBM</strong>ModuleSSL128.dll.<br />

19.Click Apply. This will add the module to the list.<br />

20.Click Submit.<br />

21.Every operation so far has been performed at the Global level. Now a new<br />

VirtualHost will be created specifically for SSL connections. Select<br />

Configuration Structure -> Create Scope.<br />

22.Select VirtualHost from the first drop-down list.<br />

23.Enter a fully-qualified name or IP address in the Virtual host name text area;<br />

in our example: websrv01.itso.ibm.com.<br />

24.Enter 443 in the Virtual host port text area.<br />

25.Enter the server name in the Server name text area, in our case:<br />

websrv01.itso.ibm.com.<br />

26.For the server path, enter the path to the /htdocs directory<br />

27.Click Submit. A new VirtualHost entry should appear in the right-hand frame.<br />

28.Select <strong>Security</strong> -> Server <strong>Security</strong>.<br />

29.Ensure the scope is set to Global. If not, click Scope and select Global.<br />

30.Enable SSL by clicking Yes.<br />

31.Enter the path and name of the key store created with the ikeyman utility.<br />

32.Enter an SSL version 2 session ID timeout of 100.<br />

33.Enter an SSL version 3 session ID timeout of 1000.<br />

34.Click Submit.<br />

35.Select <strong>Security</strong> -> Host Authorization.<br />

36.Ensure the Scope is set to the VirtualHost defined previously: websrv01.<br />

37.Enable SSL by clicking Yes.<br />

38.Click Submit.<br />

39.Restart the <strong>IBM</strong> HTTP Server. This can be performed from the command line<br />

or by clicking the Restart Server icon in the top-right corner of the<br />

284 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!