13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

In a scenario presented in this chapter, we will use LTPA for enabling SingleSign-On. For details on how to use Tivoli Access Manager WebSeal togetherwith LTPA, please refer to Chapter 12, “Tivoli Access Manager” on page 369. Therequirements for enabling Single Sign-On using LTPA are as follows.►►►►►All Single Sign-On participating servers have to use the same user registry(for example the LDAP server).All Single Sign-On participating servers must be in the same DNS domain(cookies are issued with a domain name and will not work in a domain otherthan the one for which it was issued).All URL requests must use domain names. No IP addresses or hostnamesare allowed because this will cause the cookie not to work properly.The browser must be configured to accept cookies.Server time and time zone must be correct. The Single Sign-On tokenexpiration time is absolute.All servers participating in the Single Sign-On scenario must be configured toshare LTPA keys.10.6.2 Configuring LTPA for <strong>WebSphere</strong>The following steps will guide you through the configuration of LTPA for<strong>WebSphere</strong> Application Server.1. Open the LTPA configuration panel. Launch the <strong>WebSphere</strong> AdministrativeConsole and expand the tree <strong>Security</strong> -> Authentication Mechanisms ->LTPA.2. Specify the following attributes:– Password is the password to protect LTPA keys. You will need thispassword in order to import the keys into any other SSO enabled server.Confirm the password by retyping it in the Confirm Password field.– Timeout specifies the amount of time in minutes for which the LTPA tokenwill be valid without re-authentication. For the purpose of the test, you canleave this field’s default. We have entered the value 30.Click OK to accept configuration, Key file name you will specify after settingup Single Sign-On attributes.3. Save the configuration for <strong>WebSphere</strong> to make the changes effective.4. Configure the Single Sign-On panel by clicking the link Single sign-on (SSO)at the bottom of the LTPA page.252 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!