13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

9.2.1 Extensible security architecture modelThe diagram below presents general view of the logical layered securityarchitecture model of <strong>WebSphere</strong> Application Server <strong>V5.0</strong>.The flexibility of that architecture model lies in pluggable modules that can beconfigured according to the requirements and existing IT resources.The interface layer allows you to connect different modules responsible forauthentication, authorization and user registry.The pluggable user registry allows you to configure different databases to storeuser IDs and passwords that are used for authentication. Detailed information onhow to interface to custom registry using the UserRegistry interface can be foundin Chapter 8, “Programmatic security” on page 179.NT/UnixuserregistryLDAPuserregistryCustomuserregistrySWAM LTPA JAASTivoliAccessManagerz/OSothervendor'sORBPluggable UserRegistryPluggableAuthentication<strong>WebSphere</strong> Application ServerPluggableAuthorization<strong>IBM</strong>CSIv2CSIv2<strong>IBM</strong>Figure 9-6 <strong>WebSphere</strong> V5 extensible security architectureThe pluggable authentication module allows you to choose whether <strong>WebSphere</strong>will authenticate the user or will accept the credentials from externalauthentication mechanisms. For information on how to configure <strong>WebSphere</strong> touse credentials from <strong>IBM</strong> Tivoli Access Manager, please refer to Chapter 12,“Tivoli Access Manager” on page 369. In the future, this authentication interfacewill be extended to include other external authentication systems.Pluggable authorization interfaces will allow the use of different authorizationmechanisms for <strong>WebSphere</strong> applications. In the current version, JAAS issupported and Tivoli Access Manager is an external authorization system.Chapter 9. <strong>WebSphere</strong> Application Server security 223

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!