13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

2. Save the configuration for <strong>WebSphere</strong> to have the generated keys stored inthe <strong>WebSphere</strong> configuration; they will appear in the security.xml file.3. Re-open the LTPA configuration page.4. Specify the Key File Name which is the name of the file where LTPA keys willbe stored when you export them. You need to export the keys in order toenable Single Sign-On on another server. Specify the full path name for thekey file. We have used c:\<strong>WebSphere</strong>\Appserver\etc\SSO_ltpakeys.5. Click Export Keys. Keys that have been exported in our scenario arepresented in the example below.Example 10-1 Contents of the key file generated from <strong>WebSphere</strong> LTPA panel#<strong>IBM</strong> <strong>WebSphere</strong> Application Server key file#Tue Aug 13 18:25:07 EDT 2002com.ibm.websphere.CreationDate=Tue Aug 13 18\:25\:07 EDT 2002com.ibm.websphere.ltpa.version=1.0com.ibm.websphere.ltpa.3DESKey=FDspFou4xxe1m4Il84JmAk+EXLb1QclZp7ji+BJPSDM\=com.ibm.websphere.CreationHost=wassrv01com.ibm.websphere.ltpa.PrivateKey=9qo7ytSCbTf/62bvAyExobRikGAwF4vE/vKnKe7K80eJa/jUoiAtyeo6rQumiUw/otwCBSaGWWvAHAwpTKR3CP7oJm4CAxyj0UVNF2B2iSZspH+ekZ+fS62Amp64HT+ppljshfmyjX4WZAOxRQdKpvHvX3BUMU1BjuRnlpQqp2Pov/VlBqpnSJI5vcLRrXZDCNUEA4Kd0CHcKyq5H22Iox4PiZ4rvpZ5UCXdjxfcA0rUbw+5KK1eZdVQLrcxHb/ufBQ51RrA6m2R8PCZua26RUOJwix1Y0JpGBuwKNeKDCq/pY4l70K4nkyOEXrq7EBl0VkhtC7JEsR4o5Mbc1JSbuyCJsRamjgX5/plEFZSBHE\=com.ibm.websphere.ltpa.Realm=dirsrv01.itso.ibm.com\:389com.ibm.websphere.ltpa.PublicKey=AO/uOSd3vL4zo7VUN3k8VSw9F+zpgwbRnDHmi8G8gmm5TbCKGonK4Hl+gQ9dzSDNgkDJ3BWYJEkrCj77oZsI4RCZZk1RexDqLByEO9ffR/WyT7PR4FaMMFaZo0IhaDX3GyF3yHov6l3/DcsrvYCLgO3Fc+SPsX/QnHPDQOXyKZ6lAQABAs you can see in the example, three types of keys have been generated forLTPA.► The private key, used for the LTPA server to sign the LTPA token.► The public key, used to verify the digital signature.► A shared key, used to encrypt/decrypt those tokens.10.6.4 Enabling LTPA authentication for <strong>WebSphere</strong>The following steps will show you how to enable LTPA for <strong>WebSphere</strong>Application Server.1. Select <strong>Security</strong> -> Global <strong>Security</strong> in the Administrative Console.2. Make sure that Active Authentication Mechanism is set to LTPA (Light weightThird Party Authentication).254 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!