13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Note: If the Web browser has SSL and TLS disabled, it will not be able toestablish a secure link with the IHS. In the case of Internet Explorer, SSL canbe enabled.1. From the menu bar, select Tools -> Internet Options2. Click the Advanced tab and scroll down to the <strong>Security</strong> sectionThere should be an option to enable SSL 2.0, SSL 3.0 and TLS 1.0. Bydefault, SSL versions 2 and 3 are enabled.10.10.3 Client-side certificate for client authenticationThis section discusses how to use client side certificates with your Web serverand with your <strong>WebSphere</strong> Application Server. It will also show how to configureyour servers to support client-side certificates and use them as a base for userauthentication.Obtaining a personal certificateThe Web client may also provide a digital certificate in order to assert an identityduring an SSL initialization. Typically, the creation of a client-side certificateinvolves a CA. Alternatively, the <strong>IBM</strong> Tivoli SecureWay PKI package or a similarproduct from another vendor may be used to implement a PKI solution. Thisinvolves the overhead of managing the PKI infrastructure, as well as creating theindividual certificates for each authenticating user.The process for requesting and installing a personal client-side certificate onWindows is documented in this section.For demonstration purposes, the free Personal Certificate Program offered byThawte Consulting was used. The process for requesting a personal certificatewill differ from CA to CA, with each providing different facilities.From the Thawte Web site, http://www.thawte.com, select the option to receivea free personal e-mail certificate and fill out the necessary forms. Be sure torequest an X.509v3 certificate and make certain that the e-mail address enteredis valid and can be used. The process is relatively straightforward and acertificate will be issued within a matter a minutes of registration. We got thecertificate issued, a notification was sent by Thawte about that fact, and we wentto the Thawte Web site to pick up the certificate. At the end of the process, weinstalled the certificate into the Web browser, which was Microsoft InternetExplorer in this case.Chapter 10. Administering <strong>WebSphere</strong> security 289

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!