03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Figure 10-41 Certificate details<br />

This certificate may be enabled in order to provide a client certificate when<br />

accessing Web pages over an SSL connection, with the https:// URL prefix.<br />

LDAP advanced security settings<br />

Certificate-based authentication requires either that <strong>WebSphere</strong> map the entire<br />

certificate subject Distinguished Name (DN) to a like LDAP Distinguished Name<br />

or that <strong>WebSphere</strong> certificate filtering be used to map a certificate subject<br />

Distinguished Name to a specific LDAP field for a given LDAP user.<br />

Note: As structure and hierarchy are of concern when managing an LDAP<br />

directory, it is not always possible to use the same Distinguished Name (DN)<br />

that is supported by the client side certificates.<br />

Using the <strong>WebSphere</strong> LDAP Certificate Filter option<br />

This section assumes that you have successfully installed a personal certificate<br />

into a client Web browser and that you have previously enabled <strong>WebSphere</strong><br />

Global <strong>Security</strong>, authenticating users against a remote LDAP Directory Server. It<br />

is anticipated that the personal certificate subject Distinguished Name (DN) does<br />

not necessarily match, in any way, your LDAP Distinguished Name (DN).<br />

292 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!