03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

►<br />

►<br />

Client certificate label: ClientKey<br />

Client trust file: ClientTrustFile.jks<br />

Exchange the certificates between the two parties, export the ServerKey from<br />

the ServerKeyFile.jks and import it into the ClientTrustFile.jks; export the<br />

ClientKey from the ClientKeyFile.jks and import it into the ServerTrustFile.jks.<br />

10.12.2 Server side configuration<br />

The Application Server must be configured to support SSL. An SSL configuration<br />

should exist that describes the type of key stores used to establish the secure<br />

connection and their location. Refer to 10.9.4, “Configuring <strong>WebSphere</strong> to use a<br />

key store” on page 276 for details on key stores.<br />

Note: The sas.server.props configuration file used in <strong>WebSphere</strong> Application<br />

Server, version 4 is no longer used in version 5. However, the file remains in<br />

the properties directory. The server security configuration is contained in a file<br />

called security.xml whose default location is<br />

/config/cells/BaseApplicationServerCell.<br />

Create a new SSL entry in the SSL Repertoire, following the steps in 10.8.1,<br />

“SSL configurations” on page 259 and using the following values for the<br />

attributes:<br />

►<br />

►<br />

►<br />

►<br />

►<br />

SSL alias: ORB SSL<br />

Key file: C:\<strong>WebSphere</strong>\Appserver\etc\ServerKeyFile.jks<br />

Key file password: password<br />

Trust file: C:\<strong>WebSphere</strong>\Appserver\etc\ServerTrustFile.jks<br />

Trust file password: password<br />

The authentication protocol must be configured to use the correct SSL settings.<br />

1. Log in to the <strong>WebSphere</strong> Admin console, select <strong>Security</strong> -> Authentication<br />

Protocol -> CSIv2 Inbound Authentication.<br />

2. Ensure that Basic Authentication is supported, at the very least. It is also valid<br />

to set Basic Authentication to Required.<br />

Note: When required is set to true for an attribute, where supported is also an<br />

option, the supported attribute will not be used by the server.<br />

This is true for every attribute within CSI also.<br />

Chapter 10. Administering <strong>WebSphere</strong> security 311

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!