03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Testing the secure connection<br />

To test the secure connection, use your favorite Web browser and access a Web<br />

application on <strong>WebSphere</strong> Application Server using port 9080, for example:<br />

https://wassrv01.itso.ibm.com:9080/itsobank<br />

Make sure you use the https protocol, if not, the returned page will look like this:<br />

Figure 10-45 False HTTP response<br />

In order to test the secure connection when client side certification is required,<br />

the right certificate with public and private key has to be imported into the<br />

browser.<br />

1. On the Web server machine, launch the ikeyman utility that can handle the<br />

CMS key database file.<br />

2. Open the keyfile for the plugin, in our example:<br />

c:\<strong>IBM</strong>HttpServer\conf\keys\WASplugin.kdb. Provide the password when<br />

prompted.<br />

3. Selec the WASplugin certificate under the Personal Certificates, then click<br />

Export.<br />

4. Save the certificate in PKCS12 format to a file,<br />

c:\<strong>IBM</strong>HttpServer\conf\keys\WASplugin.p12. Provide a password to secure<br />

the PKCS12 certificate file, then in the next panel select Weak encryption<br />

(browser compatible).<br />

5. Close the keyfile and quit ikeyman when you are done.<br />

6. Copy the saved WASplugin.p12 file to the client machine from which you want<br />

to access the <strong>WebSphere</strong> server.<br />

7. Import the PKCS12 file into your favorite browser. In Microsoft Internet<br />

Explorer, select Tools -> Internet Options... from the menu. Switch to the<br />

Content tab then click Certificates. Import the WASplugin.p12 certificate by<br />

using the Import... button; provide the password for the file where necessary.<br />

Chapter 10. Administering <strong>WebSphere</strong> security 309

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!