03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring the secure LDAP (LDAPS) connection<br />

This section allows you to configure the LDAP connection for <strong>WebSphere</strong><br />

Application Server V5 by following the previous steps from “Configuring a basic<br />

LDAP connection” on page 318.<br />

Creating the certificates for SSL<br />

This section provides information for the keyring settings needed for the secure<br />

LDAP connection over SSL.<br />

To create a self-signed certificate for the SecureWay LDAP peer, follow the steps<br />

described in 10.10.1, “Generating a digital certificate” on page 279.<br />

►<br />

►<br />

►<br />

Use the following information for the new LDAP keyring file:<br />

Key database file: CMS Key database file<br />

File name: LDAPKey.kdb<br />

Location: C:\LDAP\etc<br />

Use the following information to create the LDAP key entry:<br />

Key label: LDAP SSL<br />

For the rest of the fields, use your own settings according to your server and<br />

location.<br />

For extracting the certificate from the LDAP keyring file, use the following<br />

details:<br />

Data type: Base64-encoded ASCII data<br />

Certificate file name: SecurewayDAPCert.arm<br />

Location: C:\LDAP\etc<br />

To create a key database for the <strong>WebSphere</strong> LDAP SSL peer, follow the steps<br />

described in 10.9.1, “Generating a self-signed certificate” on page 264.<br />

►<br />

►<br />

►<br />

Use the following information for creating the new key database:<br />

Key Database File: JKS<br />

File Name: WASLDAPKeyring.jks<br />

Location: C:\<strong>WebSphere</strong>\AppServer\etc<br />

Use the following information to create a new self-signed certificate for LDAP:<br />

Key label: LDAPSSL<br />

For the rest of the fields, use your own settings according to your server and<br />

location.<br />

For extracting the certificate, use the following information:<br />

328 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!