03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

A sample scenario is depicted next.<br />

client01.itso.ral.ibm.com<br />

Administration client<br />

running server Web browser<br />

ndsrv01.itso.ral.ibm.com<br />

<strong>WebSphere</strong> Network Deployment<br />

running server dmgr<br />

appsrv01.itso.ral.ibm.com<br />

<strong>WebSphere</strong> Application Server<br />

running NodeAgent<br />

running server1<br />

appsrv01.itso.ral.ibm.com<br />

<strong>WebSphere</strong> Application Server<br />

running NodeAgent<br />

running server1<br />

Figure 10-63 <strong>WebSphere</strong> cell with one deployment manager and two application servers<br />

There are differences in the runtime environment from the security and from the<br />

system management points of view when you federate your application servers<br />

under one cell, managed by a Network Deployment manager.<br />

►<br />

►<br />

►<br />

The administrator application disappears and is uninstalled from the<br />

individual nodes. All the management takes place from the Network<br />

Deployment manager, providing one single access point for administration.<br />

The embedded JMS servers are detached from the application servers. While<br />

the embedded JMS server depends on the application server when running a<br />

base application server, in a federated cell, the embedded JMS server is<br />

running separately from the application server, and they are managed<br />

individually.<br />

In a federated cell, only LTPA (Lightweight Third Party Authentication) is<br />

available as an authentication mechanism for the individual servers. The main<br />

point is that SWAM (Simple <strong>WebSphere</strong> Authentication Mechanism) cannot<br />

work anymore, because we need to pass credental information between<br />

servers.<br />

– CSIv2 takes care of passing credentials between EJB containers.<br />

– LTPA takes care of passing credentials between Web containers by<br />

enabling Single Sign-On for the Cell.<br />

338 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!