03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

[8/22/02 7:42:47:449 CDT] 277a2e5c Util < toString(array)<br />

[8/22/02 7:42:47:449 CDT] 277a2e5c ltpaLoginModu d cred token = <br />

[8/22/02 7:42:47:449 CDT] 277a2e5c ltpaLoginModu d Successfully gathered<br />

authentication information<br />

[8/22/02 7:42:47:449 CDT] 277a2e5c ltpaLoginModu d Using uid and password for<br />

authentication<br />

[8/22/02 7:42:47:449 CDT] 277a2e5c ltpaLoginModu d Authenticating<br />

"null/tai_user"<br />

[8/22/02 7:42:47:449 CDT] 277a2e5c LTPAServerObj > authenticate<br />

[8/22/02 7:42:47:449 CDT] 277a2e5c LTPAServerObj < authenticate<br />

[8/22/02 7:42:47:449 CDT] 277a2e5c UserRegistryI > checkPassword<br />

[8/22/02 7:42:47:449 CDT] 277a2e5c LdapRegistryI > checkPassword<br />

[8/22/02 7:42:47:449 CDT] 277a2e5c LdapRegistryI d Authenticating<br />

tai_user<br />

[8/22/02 7:42:47:450 CDT] 277a2e5c LdapRegistryI d Searching for users<br />

[8/22/02 7:42:47:450 CDT] 277a2e5c LdapRegistryI > getUsers<br />

tai_user<br />

[8/22/02 7:42:47:450 CDT] 277a2e5c LdapRegistryI > search<br />

[8/22/02 7:42:47:450 CDT] 277a2e5c LdapRegistryI d DN: o=itso<br />

[8/22/02 7:42:47:450 CDT] 277a2e5c LdapRegistryI d Search scope: 2<br />

[8/22/02 7:42:47:450 CDT] 277a2e5c LdapRegistryI d Filter:<br />

(&(uid=tai_user)(objectclass=inetOrgPerson))<br />

...<br />

[[8/22/02 7:42:47:453 CDT] 277a2e5c LdapRegistryI d Found user<br />

cn=tai_user,o=itso<br />

[8/22/02 7:42:47:453 CDT] 277a2e5c LdapRegistryI > checkStopped<br />

[8/22/02 7:42:47:453 CDT] 277a2e5c LdapRegistryI < checkStopped<br />

[8/22/02 7:42:47:486 CDT] 277a2e5c LdapRegistryI d Time elapsed to open/close<br />

DirContext: 33<br />

[8/22/02 7:42:47:486 CDT] 277a2e5c LdapRegistryI d Authenticated with<br />

cn=tai_user,o=itso<br />

[8/22/02 7:42:47:486 CDT] 277a2e5c LdapRegistryI < checkPassword<br />

cn=tai_user,o=itso<br />

[8/22/02 7:42:47:486 CDT] 277a2e5c UserRegistryI d user cn=tai_user,o=itso<br />

password checks ok<br />

In this section of the trace, we see that TAI is processing the header information<br />

provided by our WebSEAL server, and is authenticating the WebSEAL server,<br />

using the user id and password provided with the -B option. If the id or password<br />

you set in your junction is invalid, this will show up as an authentication error. In<br />

this example, the id passed to <strong>WebSphere</strong> is tai_user, and <strong>WebSphere</strong> was able<br />

to successfully authenticate the WebSEAL server.<br />

In this final section of the trace, once <strong>WebSphere</strong> has authenticated our<br />

WebSEAL server, the user identity passed by WebSEAL will be used for this<br />

request. In our example, the user ID passed is manager. <strong>WebSphere</strong> will locate<br />

the user ID passed in the user registry, and then use this identity to process the<br />

406 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!