03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

[10/14/02 19:39:38:358 EDT] 7a376025 < UOW=<br />

source=com.ibm.ws.security.registry.ldap.LdapRegistryImpl org=<strong>IBM</strong><br />

prod=<strong>WebSphere</strong> component=Application Server<br />

getGroupsForUser<br />

[10/14/02 19:39:38:358 EDT] 7a376025 < UOW=<br />

source=com.ibm.ws.security.registry.ldap.LdapRegistryImpl org=<strong>IBM</strong><br />

prod=<strong>WebSphere</strong> component=Application Server<br />

getUniqueGroupIds<br />

[10/14/02 19:39:38:358 EDT] 7a376025 < UOW=<br />

source=com.ibm.ws.security.registry.ldap.LdapRegistryImpl org=<strong>IBM</strong><br />

prod=<strong>WebSphere</strong> component=Application Server<br />

createCredential parm1=CN=manager01, O=itso<br />

...<br />

10.11 SSL between the Web server and <strong>WebSphere</strong><br />

This section documents the configuration necessary to instantiate a secure<br />

connection between the Web server plug-in and the embedded HTTP server in<br />

the <strong>WebSphere</strong> Web container. By default, this connection is not secure, even<br />

when Global <strong>Security</strong> is enabled. The documentation will cover the configuration<br />

for <strong>IBM</strong> HTTP Server 1.3.24, but the Web server related configuration in this<br />

situation is not specific to any Web server.<br />

Set the authentication mechanism as client-cert<br />

The following steps are mandatory for generating the certificates for SSL<br />

communication between the two differing peers.<br />

1. Create a self-signed certificate for the Web server plug-in.<br />

2. Create a self-signed certificate for the <strong>WebSphere</strong> embedded HTTP Server<br />

(Web Container).<br />

3. Exchange the public keys between the two peers.<br />

4. Modify the Web server plugin-cfg.xml file to use SSL/HTTPS.<br />

5. Modify the <strong>WebSphere</strong> embedded HTTP Server (Web Container) to use<br />

SSL/HTTPS.<br />

302 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!