13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

9.2.2 <strong>WebSphere</strong> Application Server security componentsThe <strong>WebSphere</strong> Application Server security components are listed below.User registryThe user registry stores user and group names for authentication andauthorization purposes. Authentication mechanisms configured for <strong>WebSphere</strong>Application Server consult the user registry to collect user related informationwhen creating credentials, which are then used to represent the user forauthorization. The options for user registries include:►►►Local operating system user registry - when configured, <strong>WebSphere</strong> usesthe operating system’s users and groups for authentication. When configuring<strong>WebSphere</strong> Application Server on Windows NT or Windows 200 platformsthat are connected to a Windows domain, you should be aware that domainuser registry takes precedence over a local machine’s user registry.LDAP user registry - in many solutions, LDAP user registry is recommendedas the best solution for large scale Web implementations. Most of the LDAPservers available on the market are well equipped with security mechanismsthat can be used to securely communicate with <strong>WebSphere</strong> ApplicationServer. <strong>WebSphere</strong> supports a few LDAP servers: <strong>IBM</strong> SecureWay Directory,Netscape LDAP Server, Lotus Domino LDAP Server, Microsoft ActiveDirectory. There is also the possibility to use other LDAP servers. Theflexibility of search parameters that an administrator can set up to adapt<strong>WebSphere</strong> to different LDAP schemas is considerable.Custom user registry - this leaves an open door for any customimplementation of a user registry database. <strong>WebSphere</strong> API provides theUserRegistry Java interface that you should use to write the custom registry.This interface may be used to access virtually any relational database, flatfiles and so on.The <strong>WebSphere</strong> authentication mechanism cannot be configured to use morethan one user registry at a time. Only one single active registry is supported andit is set up when configuring Global <strong>Security</strong> settings using the AdministrationConsole.Authentication mechanismsAn authentication mechanism defines rules about security information, forexample, whether a credential is forwardable to another Java process, and theformat in which security information is stored in both credentials and tokens.Authentication is the process of establishing whether a client is valid in aparticular context. A client can be either an end user, a machine, or anapplication.224 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!