03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

In the following sample, we will use Thawte’s personal certificate requested<br />

through the Free Certificate Program.<br />

Take a look at the certificate details in Figure 10-41 on page 292; the Subject<br />

attribute of the certificate equates the certificate SubjectDN, and the value in our<br />

case is:<br />

E = testwebclient@yahoo.com<br />

CN = Thawte Freemail Member<br />

If you used an alternative PKI solution, the subjectDN will be different, but equally<br />

unique, with the issuer (signer) value being different.<br />

Another alternative to see the SubjectDN for a certificate is to use the Java<br />

keytool utility. Export the public certificate from the browser using the Base-64<br />

encoded format for the export, then run the following command:<br />

keytool -printcert -file <br />

The result for our example was:<br />

Owner: EmailAddress=testwebclient@yahoo.com, CN=Thawte Freemail Member<br />

Issuer: CN=Personal Freemail RSA 2000.8.30, OU=Certificate Services,<br />

O=Thawte, L=Cape Town, ST=Western Cape, C=ZA<br />

Serial number: 8183a<br />

Valid from: Thu Aug 15 10:56:15 EDT 2002 until: Fri Aug 15 10:56:15 EDT<br />

2003<br />

Certificate fingerprints:<br />

MD5: C5:55:B4:CD:42:19:3D:A2:54:F0:66:E7:20:31:CE:3D<br />

SHA1: D0:14:77:5F:8E:0B:FB:80:57:CD:F7:7E:49:DF:7C:52:FE:20:2B:67<br />

The SubjectDN is the value of the Owner attribute, which is:<br />

EmailAddress=testwebclient@yahoo.com, CN=Thawte Freemail Member<br />

The next step is to modify <strong>WebSphere</strong> LDAP filtering rules to map the certificate<br />

subjectDN field to the <strong>IBM</strong> SecureWay LDAP uniqueIdentifier field for a given<br />

user. You do not necessarily have to use the SecureWay LDAP uniqueIdentifier<br />

field. However, you should ensure that the data type of the field selected is<br />

capable of handling the specific value and the certificate attribute selected for<br />

authentication is unique between certificates.<br />

Also ensure that <strong>WebSphere</strong> has the right to search such a field when<br />

performing authentication.<br />

Chapter 10. Administering <strong>WebSphere</strong> security 293

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!