03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Table 10-7 <strong>IBM</strong> SAS-specific sas.client.props configuration<br />

Property<br />

com.ibm.ssl.sas.outbound.keyStore<br />

com.ibm.ssl.sas.outbound.keyStorePassword<br />

com.ibm.ssl.sas.outbound.keyStoreType<br />

com.ibm.ssl.sas.outbound.trustStore<br />

com.ibm.ssl.sas.outbound.trustStorePassword<br />

com.ibm.ssl.sas.outbound.trustStoreType<br />

com.ibm.ssl.sas.outbound.protocol<br />

Value<br />

<br />

<br />

JKS<br />

<br />

<br />

JKS<br />

SSLv3<br />

Once SSL is configured, use the launchclient tool provided with <strong>WebSphere</strong> to<br />

test the connection. It may be feasible to run a packet monitoring tool to be sure<br />

that the information passing from client to server is, in fact, encrypted. Only the<br />

server and client certificates should be sent in the clear and then only during the<br />

initialization stage. In any case, these certificates are considered to be viewable<br />

by the public in general as they do not contain any private information.<br />

Should an error occur, the likelihood is that a Java exception trace will appear in<br />

the client console. Often the errors refer to CORBA problems, CORBA being the<br />

underlying marshalling mechanism with which the ORBs operate. Most CORBA<br />

exceptions are difficult to interpret due to their somewhat terse messages.<br />

Tracing can also provide a useful insight to the events that led up to the error.<br />

10.13 Connecting to directory servers (LDAP)<br />

This section will discuss the LDAP User Registry configuration for the<br />

<strong>WebSphere</strong> Application Server. The user registry we used to show the<br />

configuration steps is the <strong>IBM</strong> SecureWay Directory Server V3.2.2. This section<br />

will show you how to configure your LDAP server for this sample, and how to<br />

create a sample user and a sample group entry in the directory. We provide an<br />

example of how to configure <strong>WebSphere</strong> to use a given LDAP server over a<br />

normal LDAP connection, then use SSL for LDAP (LDAPS).<br />

For other LDAP servers, refer to Appendix B, “LDAP configurations” on<br />

page 461.<br />

Chapter 10. Administering <strong>WebSphere</strong> security 317

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!