13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

SSL connection #1 SSL connection #2Web server's certificateApplication server certificateBrowser's certificateWeb server's certificateWeb browserclientWeb server<strong>WebSphere</strong>ApplicationserverFigure 10-32 How certificates are distributed during an SSL connection initializationFigure 10-32 shows how certificates are exchanged during an SSL handshake.An SSL handshake occurs while the connection between the two components isbeing established and it is during this time that the identities of the server and theclient are transferred, should this option be selected. A single SSL connectionwill not span multiple servers and so the first SSL connection in this exampleexists between the Web browser and the Web server. The second SSLconnection, which initiates a second handshake, exists between the Web serverand the <strong>WebSphere</strong> Application Server. During the first handshake, the Webserver’s and Web browser’s certificates are exchanged and during the secondhandshake, the Application Server’s and Web server’s certificates areexchanged.Using wsadminIt is possible to add an SSL configuration to the repository using the wsadmintool, rather than the Administrative Console. Refer to Appendix D, “Usingwsadmin scripting for security configuration” on page 513 for further informationon this topic and some sample scripts.10.10 SSL between the Web client and the Web server<strong>IBM</strong>'s HTTP Server (IHS), as of version 1.3.26, supports SSL version 3 andversion 2 and TLS version 1. While IHS is based on the Apache Web server, it isnecessary to use the <strong>IBM</strong>-supplied SSL modules, rather than the OpenSSLvarieties. This section will describe configuration of the IHS, although it is entirelypossible that another supported Web server is used in its place.SSL is disabled by default and it is necessary to modify a configuration file andgenerate a server-side certificate using the ikeyman tool provided with IHS inorder to enable SSL.278 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!