13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring Client02Client02 requires transport layer authentication using SSL client certificates; toaccomplish this, follow the steps below:1. The client needs to point to the sas.client.props file using the propertycom.ibm.CORBA.ConfigURL=file:/c:/websphere/appclient/properties/sas.client.props.2. All further configuration involves setting properties within the sas.client.propsfile, open it in a text editor in the /propertiesdirectory.3. Enable SSL for the connection, in this case, SSL will be supported but notrequired: com.ibm.CSI.performTransportAssocSSLTLSSupported=true,com.ibm.CSI.performTransportAssocSSLTLSRequired=false.4. Disable client authentication at the message layer.com.ibm.CSI.performClientAuthenticationRequired=falsecom.ibm.CSI.performClientAuthenticationSupported=false5. Enable client authentication at the transport layer. Here we are supporting itand not requiring it:com.ibm.CSI.performTLClientAuthenticationRequired=false,com.ibm.CSI.performTLClientAuthenticationSupported=true.6. Save the file then close it.Configuring Server02In the Web Console, Server02 will be configured for incoming requests to SSLclient authentication and Identity Assertion. Configuration for outgoing requestsis not relevant for this scenario. Follow the steps below to configure Server02.Configure Server02 for incoming connections.1. Configure Server02 for incoming connections. Start the AdministrativeConsole for Server02, then navigate to the <strong>Security</strong> -> AuthenticationProtocol section.2. Select CSIv2 Incoming Authentication.a. Disable Basic authentication, by selecting Never.b. Enable Client Certificate Authentication by selecting Supported.c. Enable Identity Assertion.3. Select CSIv2 Incoming Transport.Enable SSL by selecting SSL-Supported.114 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!