13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

3. Enable SSL for the connection, in this case, SSL will be supported but notrequired: com.ibm.CSI.performTransportAssocSSLTLSSupported=true,com.ibm.CSI.performTransportAssocSSLTLSRequired=false.4. Disable client authentication at the message layer.com.ibm.CSI.performClientAuthenticationRequired=false,com.ibm.CSI.performClientAuthenticationSupported=false.5. Enable client authentication at the transport layer. Here we are supporting itand not requiring it:com.ibm.CSI.performTLClientAuthenticationRequired=false,com.ibm.CSI.performTLClientAuthenticationSupported=true.6. Save the file then close it.Configuring Server01In the Web Console, Server01 will be configured for incoming connections tosupport SSL with client certificate authentication. Server01 will be configured foroutgoing requests to support message layer client authentication. Follow thesteps below to configure Server01:1. Configure Server01 for incoming connections. Start the AdministrativeConsole for Server01, then navigate to the <strong>Security</strong> -> AuthenticationProtocol section.a. Select CSIv2 Inbound Authentication.i. Disable Basic Authentication, by selecting Never.ii. Enable Client Certificate Authentication by selecting Supported.iii. Disable Identity Assertion.b. Select CSIv2 Inbound Transport.Enable SSL by selecting SSL-Supported.2. Configure Server01 for outgoing connections.a. Select CSIv2 Outbound Authentication.i. Disable Basic Authentication by selecting Never.ii. Enable Client Certificate Authentication by selecting Supported.iii. Disable Identity Assertion.b. Select CSIv2 Outbound Transport.Enable SSL by selecting SSL-Supported.116 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!