03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

3. If you decide the use the <strong>IBM</strong> HTTP Server Administrative Console, log in to<br />

the <strong>IBM</strong> HTTP Server Administrative Console as documented in 10.10.2,<br />

“Configuring the <strong>IBM</strong> HTTP Server” on page 281.<br />

4. Select <strong>Security</strong> -> Host Authorization from the left-side navigator.<br />

5. Click the Scope button, and select your virtual host from the list that appears<br />

in a new window, in our case: .<br />

The new setting should appear next to the Scope button.<br />

6. Change the Mode of client authentication to use to Required.<br />

7. Submit the changes using the button at the bottom.<br />

8. Restart the Web server.<br />

Note: If you choose to edit the httpd.conf file manually, open it with your<br />

favorite browser from the \conf directory, then find the SSL<br />

configuration part. It should start with the definition of a new VirtualHost, for<br />

example: . Find the SSLEnable<br />

directive then insert the following directive:<br />

SSLClientAuth required<br />

Save the httpd.conf file, then close it and finally restart the Web server.<br />

9. <strong>WebSphere</strong> Application Server does not support the port 443 by default; you<br />

have to modify the default host configuration. Log in to the <strong>WebSphere</strong><br />

Administration Console, then select: Environment -> Virtual Hosts, then<br />

click Default host.<br />

10.Select Host aliases, click New, then provide the following values:<br />

Host Name: *<br />

Port: 443<br />

Click OK when you are finished.<br />

11.Save the configuration for <strong>WebSphere</strong>.<br />

12.You have to stop and restart the server to make the changes effective.<br />

Testing the client side certificate<br />

The best way to test the client certificate is to use the Default Application that<br />

ships with <strong>WebSphere</strong> and use the snoop servlet by accessing it with your Web<br />

browser. Access the following address from the client:<br />

https:///snoop, to determine if your browser is correctly<br />

passing a client certificate.<br />

296 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!