03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

In this example, we have configured one login form page, login-itsobank. The<br />

URI for our login form is /itsobank/login/login.html. This entry defines for<br />

WebSEAL the URI that should be intercepted. When a request is received for<br />

this URI, WebSEAL will intercept the form, and will return to our ITSOBank<br />

application the GSO user ID and password defined for this Acess Manager user<br />

in the was50 GSO resource. If the user does not have a GSO ID and password<br />

defined for was50, then WebSEAL will return an error page to the user to inform<br />

them that they cannot login to the itsobank application.<br />

We now need to create a junction to our back-end <strong>WebSphere</strong> server, using the<br />

-S parameter. Once we have done this, Single Sign-On forms authentication will<br />

be enable. The syntax of the junction command is:<br />

pdadmin> server task Webseald-WebSEALServer create -f -t tcp -p portnumber -h<br />

<strong>WebSphere</strong>ServerName -S path/filename.conf /JunctionName<br />

Where the following arguments are defined:<br />

► WebSEALServer is the host name of your WebSEAL server, for example:<br />

wsl01.<br />

► portnumber is the port number to connect to <strong>WebSphere</strong>, for example: 9443.<br />

►<br />

►<br />

►<br />

<strong>WebSphere</strong>ServerName is the host name of your <strong>WebSphere</strong> server, for<br />

example: appsrv01.<br />

path/filename.conf is the full path and name of your configuration file.<br />

JunctionName is the name you with to assign to this junction, for example:<br />

/tai.<br />

After creating your junction, any request which causes the itsobank application to<br />

present the login.html form will be intercepted by WebSEAL, and WebSEAL will<br />

provide the users id and password back to the ITSOBank sample application.<br />

The end user will never be aware that a login to ITSOBank sample application<br />

was performed on his behalf.<br />

12.4.3 Tivoli Access Manager plug-in for <strong>WebSphere</strong> Edge Server<br />

The <strong>WebSphere</strong> Edge Server is a collection of applications designed to improve<br />

Web and application server performance and availability by load balancing<br />

servers, intelligently caching static content, and by moving content delivery as<br />

close to the users, from a network perspective, as possible. The “edge of the<br />

network” is normally the DMZ between an organization’s intranet and the public<br />

Internet, and it is into this DMZ that the <strong>WebSphere</strong> Edge Server components<br />

are deployed.<br />

410 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!