13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

The CSIv2 configuration properties are listed below. Certain security propertieshave supported/required property pairs. If the required property is enabled thencommunication with the server must satisfy this property.►►►►►►com.ibm.CSI.performStateful (true, false / true) - determines whether theauthentication request should result in a stateful reply returning from theserver.com.ibm.CSI.performTLClientAuthenticationRequired (true, false / false) andcom.ibm.CSI.performTLClientAuthenticationSupported (true, false / false) -determines if transport-layer client authentication is required or supported.This will involve the client sending a digital certificate to the server during theauthentication stage. If the Required property is set to true, the client will onlyauthenticate with servers that support transport-layer client authentication.com.ibm.CSI.performTransportAssocSSLTLSRequired (true, false / false)and com.ibm.CSI.performTransportAssocSSLTLSSupported (true, false /true) - determines if the client can use SSL to communicate with the server. Ifthe Required property is set to true, the client will only communicate withservers that support SSL.com.ibm.CSI.performClientAuthenticationRequired (true, false / true) andcom.ibm.CSI.performClientAuthenticationSupported (true, false / true) -determines if message layer client authentication is required or supported.The com.ibm.CORBA.authenticationTarget property determines the type ofauthentication mechanism.com.ibm.CSI.performMessageIntegrityRequired (true, false / true) andcom.ibm.CSI.performMessageIntegritySupported (true, false / true) -determines if a connection secured by a 40-bit cipher is supported orrequired. If the Required property is set to true then the connection will fail ifthe server does not support 40-bit ciphers. This property is only valid whenSSL is enabled.com.ibm.CSI.performMessageConfidentialityRequired (true, false / false) andcom.ibm.CSI.performMessageConfidentialitySupported (true, false / true) -determines if a connection secured by a 128-bit cipher is supported orrequired. If the Required property is set to true then the connection will fail ifthe server does not support 128-bit ciphers. This property is only valid whenSSL is enabled.For a more complete list of directives, refer to the <strong>WebSphere</strong> Application ServerInfoCenter for more details.The Application Server should also be configured to communicate with a client inthe required fashion. If a Java client requires that client certificates be transmittedvia SSL, for example, then the server must be set to expect this. Details on theconfiguration of the Application Server can be found in Chapter 10,“Administering <strong>WebSphere</strong> security” on page 233.106 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!