03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The Policy Server replicates this database to all the local authorization servers,<br />

including WebSEAL, throughout the domain, publishing updates as required. The<br />

Policy Server also maintains location information about the other Access<br />

Manager and non-Access Manager servers operating in the secure domain.<br />

There can be only one Policy Server active within a domain.<br />

Access Manager provides C and Java authorization APIs which can be used<br />

programmatically within other applications and clients. Client calls for<br />

authorization decisions, through the Access Manager Run-time service, which<br />

must be on every server participating in the secure domain, are always referred<br />

to an Authorization Server. Programatically made calls can be local or remote;<br />

they will be passed to an Authorization Server. When running local node API, the<br />

application communicates to the security server (Access Manager), no<br />

authorization server is required.<br />

Authorization servers are the decision-making servers that determines a client's<br />

ability to access a protected resource based on the security policy. Each server<br />

has a local replica of the policy database. There must be at least one within a<br />

Secure Domain.<br />

Web Portal Manager, a <strong>WebSphere</strong>-hosted application is provided to enter and<br />

modify the contents of the policy store and the user registry. There is also a<br />

command line utility, pdadmin, which extends the available commands available<br />

to include the creation and registration of authentication blades such as<br />

WebSEAL which will be described a little later.<br />

Access Manager can be configured to integrate with many of the <strong>WebSphere</strong><br />

branded products and ships with explicit plug-ins for the following products:<br />

►<br />

►<br />

►<br />

<strong>WebSphere</strong> Application Server.<br />

<strong>WebSphere</strong> Edge Server<br />

BEA Robotic Application Server<br />

► Web Server Plug-in, which supports IIS 5.0 for a Windows 2000<br />

Server/Advanced Server environment, iPlanet 6.0 for Solaris Operating<br />

Environment 7 (sparc) and IHS 1.3.19 for an AIX 5L environment.<br />

The list of point products and components shipped in the Tivoli Access Manager<br />

V3.9 package can be found in Table 12-1 on page 377.<br />

376 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!