03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Property key<br />

com.ibm.Websphere.security.Webseal.loginID<br />

com.ibm.Websphere.security.Webseal.mutualSSL<br />

Value<br />

This property specifies the userID<br />

(e.g. tai_user in the scenario<br />

above) which will be<br />

authenticated, using the<br />

password appearing in the HTTP<br />

Basic Authentication (BA) header<br />

to validate the incomming<br />

request. If this property is used,<br />

the userID appearing in the BA<br />

header is ignored. If this property<br />

is not used, the interceptor<br />

authenticates using both the<br />

userID and password appearing<br />

in the BA header. This property<br />

has no effect when the<br />

mutualSSL property is set to true.<br />

If this property is set to true, the<br />

WebSEAL interceptor implicitly<br />

trusts that the WeEAL junction<br />

has been secured through the<br />

use of one of WebSEAL’s<br />

mutually authenticated SSL<br />

junction capabilities. When this<br />

property is set to true, the<br />

interceptor skips the<br />

authentication step in the<br />

validation of the request.<br />

Important: Setting the mutualSSL property to true effectively disables one of<br />

the mechanisms of validating the WebSEAL server and its authentication of<br />

the client’s identity. In some instances, it may be sufficient for the interceptor to<br />

validate the request on the basis of the originating hostname and port, but in<br />

general this should be done with caution.<br />

Important: If the interceptor ignores or fails to validate a request, the<br />

<strong>WebSphere</strong> security runtime will proceed to handle the request as if the<br />

interceptor had not been enabled. In other words, requests that are not<br />

handled by the interceptor are not rejected, but rather are passed unchanged<br />

to the security runtime.<br />

394 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!