03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

1. Open the ikeyman tool that comes with <strong>WebSphere</strong>, able to handle the .jks<br />

files, then open the server trust store file; if you are using the dummy<br />

keystore, open the \etc\DummyServerTrustFile,jks.<br />

2. Import the LDAPSSLServer.arm as a signer certificate; use the file from the<br />

Domino server, you will have to copy the .arm file to your <strong>WebSphere</strong> server<br />

machine.<br />

3. Close the ikeyman utility.<br />

To create a new SSL entry and configure <strong>WebSphere</strong> to use it to connect to the<br />

LDAP server, follow the steps from “Configuring the secure LDAP (LDAPS)<br />

connection” on page 328 using the following information.<br />

iPlanet Directory Server<br />

In this section, we will cover the steps required to configure <strong>WebSphere</strong> with<br />

Netscape’s iPlanet Directory Server <strong>V5.0</strong>. In this scenario, we have installed<br />

Access Manager using the native installation method.<br />

Configuring <strong>WebSphere</strong> to use iPlanet Directory Server<br />

In order to configure <strong>WebSphere</strong>’s access to iPlanet Directory Server, we must<br />

first define a user entry for <strong>WebSphere</strong> to use for binding to the directory, as we<br />

did for <strong>IBM</strong> Directory Server.<br />

The only change we have made is that we are now using a directory suffix of<br />

o=tamral,c=us instead of o=itso.<br />

After you have created your user entry, <strong>WebSphere</strong> is ready to be configured to<br />

use iPlanet Directory Server as its user registry.<br />

1. Start the <strong>WebSphere</strong> Administrator’s Console. Once you have started the<br />

console, log in and select <strong>Security</strong> -> User Registries -> LDAP. This will<br />

display the LDAP User Registry panel.<br />

2. Fill out the LDAP configuration page as follows:<br />

– Server User ID: enter either the fully qualified Distinguished Name (DN) or<br />

the <strong>WebSphere</strong> server ID user; we used the DN:<br />

cn=wasadmin,o=tamral,c=us.<br />

– Server User Password: enter the password for your user ID.<br />

– Type: Netscape.<br />

– Host: enter the fully qualified DNS name of your iPlanet Directory Server.<br />

In our configuration, our host name is tivoli9.svo.dfw.ibm.com.<br />

– Port: 389<br />

472 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!