03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Tip from a battle scarred veteran prodigy “grasshopper”:<br />

You really, really need to create a new keystore file. If you don’t, you will get to<br />

spend this Friday night in the lab, like those poor <strong>IBM</strong> Directory Server folks<br />

who ignored my tip got to do last Friday night. Of course, you didn’t read my<br />

tip to them, did you? That makes perfect sense, as you are working with<br />

iPlanet Directory Server. May I suggest that you refer to my tip in their section.<br />

Then you can decide how you want to spend this Friday night.<br />

To create our keystore file, follow the steps from “Generating a self-signed<br />

certificate for the Web Container” on page 304.<br />

Create a new key database using the following information:<br />

► Key database type: JKS<br />

► File name: iPlanet.jks<br />

► Location: /usr/<strong>WebSphere</strong>/AppServer/etc<br />

Import the certificate using the following information:<br />

► Certificate format: Base64-encoded ASCII data<br />

► Certificate file name: export_Tivoli10.cer<br />

► Location: /tmp<br />

Now that we have our keystore file, we are ready to begin the configuration of<br />

<strong>WebSphere</strong> for SSL access to our directory server. To begin, log in to your<br />

<strong>WebSphere</strong> Administrative Console from your browser, and follow these steps.<br />

1. The first thing we need to do is to define the SSL settings to use our keystore<br />

file. Follow the steps from 10.8.1, “SSL configurations” on page 259 using the<br />

information below:<br />

►<br />

►<br />

►<br />

►<br />

►<br />

►<br />

►<br />

►<br />

Alias: iPlanetssl<br />

Key File Name: /usr/<strong>WebSphere</strong>/AppServer/etc/iPlanetkey.jks<br />

Key File Password: type in the password for the key file<br />

Key File Format: JKS<br />

Trust File Name: /usr/<strong>WebSphere</strong>/AppServer/etc/iPlanetkey.jks<br />

Trust File Password: type in the password for the key file<br />

Trust File Format: JKS<br />

<strong>Security</strong> Level: High<br />

484 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!