03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

SSO Domino - <strong>WebSphere</strong><br />

SSO <strong>WebSphere</strong> - Domino<br />

LDAP server<br />

LDAP server<br />

4<br />

LDAP<br />

DB2<br />

LDAP<br />

DB2<br />

4<br />

5<br />

5<br />

Domino server<br />

<strong>WebSphere</strong><br />

server<br />

Domino server<br />

<strong>WebSphere</strong><br />

server<br />

webbank<br />

database<br />

Webbank<br />

application<br />

webbank<br />

database<br />

Webbank<br />

application<br />

2 3 6<br />

1<br />

7<br />

8<br />

8<br />

7<br />

1<br />

2<br />

36<br />

Figure C-1 Sample SSO Domino - <strong>WebSphere</strong> using <strong>IBM</strong> SecureWay Directory<br />

1. A Web user requests a protected resource from the Web server. In the case<br />

of Domino Server, the request is to enter a comment into the<br />

ITSOBankComments database, for instance if a <strong>WebSphere</strong> user requests a<br />

bank transfer.<br />

2. The Web server prompts the user for the authentication information.<br />

3. The user responds to the challenge by supplying the information (user name<br />

and password or certificate).<br />

4. The Web Server contacts the LTPA server (Domino or <strong>WebSphere</strong>) which<br />

connects with the <strong>IBM</strong> SecureWay Directory to verify the authentication<br />

information.<br />

5. If the information supplied for the user is correct, the <strong>IBM</strong> SecureWay<br />

Directory responds to the LTPA server with the validated information.<br />

6. The LTPA server uses the returned values to check whether the user has<br />

access to the requested resource and issues an LTPA token for the user. The<br />

Web server sends the token to the user as an HTTP cookie, which is stored in<br />

the user’s browser, and serves the requested resource (opening the<br />

ITSOBankComments database in the case of Domino or<br />

CustomerTransfer.html in the case of <strong>WebSphere</strong>).<br />

Appendix C. Single Sign-On with Lotus Domino 493

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!