13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

►System exactly matches the principal in the application server. WithCredentials Mapping the type of credentials must be mapped fromapplication server credentials to Enterprise Information System credentials.Though it is easy to have container-managed sign-on, there is little flexibilityas it is not possible to change the security properties in runtime.Component-managed sign-on allows you to pass security configurationproperties each time a connection is acquired from the resource adapter.7.3.2 Java 2 Connector securityThe Enterprise Information System stores very important information and theinformation must be protected from unauthorized users. Java 2 Connectorarchitecture is designed to address the security of connection to EnterpriseInformation System. The application server and the Enterprise InformationSystem collaborate to ensure the proper authentication of a resource principalwhich establishes a connection to an underlying enterprise information system.Connector architecture supports the following authentication mechanisms:►►BasicPassword: Basic username-password based authentication mechanismspecific to enterprise information system.Kerbv5: Kerberos version 5 based authentication model<strong>WebSphere</strong> Application Server V5 Java 2 Connector supports basic passwordmodel currently. Kerberos authentication model will be supported in the nearfuture.The user ID and password for the target EIS is either supplied by applications orby the application server. <strong>WebSphere</strong> Application Server uses the JAASpluggable authentication mechanism to perform principal mapping to convert<strong>WebSphere</strong> principal to resource principal. <strong>WebSphere</strong> Application Serverprovides a DefaultPrincipalMapping LoginModule, which basically converts anyauthenticated principal to the pre-configured EIS resource principal andpassword. Subsequently, you can plug in your own principal mappingLoginModule using the JAAS plug-in mechanism.The user ID and password can either be configured using the AdministrativeConsole or can be sent to the Enterprise Information System programmatically.Using J2C Authentication Data Entries for DatasourceFirst, you will have to create a new J2C entry for <strong>WebSphere</strong>. In order to createthe appropriate entry for this section follow the configuration steps from 10.7.2,“J2C Authentication data entries” on page 257.Chapter 7. Securing Enterprise Integration components 171

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!