13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

In the following sample, we will use Thawte’s personal certificate requestedthrough the Free Certificate Program.Take a look at the certificate details in Figure 10-41 on page 292; the Subjectattribute of the certificate equates the certificate SubjectDN, and the value in ourcase is:E = testwebclient@yahoo.comCN = Thawte Freemail MemberIf you used an alternative PKI solution, the subjectDN will be different, but equallyunique, with the issuer (signer) value being different.Another alternative to see the SubjectDN for a certificate is to use the Javakeytool utility. Export the public certificate from the browser using the Base-64encoded format for the export, then run the following command:keytool -printcert -file The result for our example was:Owner: EmailAddress=testwebclient@yahoo.com, CN=Thawte Freemail MemberIssuer: CN=Personal Freemail RSA 2000.8.30, OU=Certificate Services,O=Thawte, L=Cape Town, ST=Western Cape, C=ZASerial number: 8183aValid from: Thu Aug 15 10:56:15 EDT 2002 until: Fri Aug 15 10:56:15 EDT2003Certificate fingerprints:MD5: C5:55:B4:CD:42:19:3D:A2:54:F0:66:E7:20:31:CE:3DSHA1: D0:14:77:5F:8E:0B:FB:80:57:CD:F7:7E:49:DF:7C:52:FE:20:2B:67The SubjectDN is the value of the Owner attribute, which is:EmailAddress=testwebclient@yahoo.com, CN=Thawte Freemail MemberThe next step is to modify <strong>WebSphere</strong> LDAP filtering rules to map the certificatesubjectDN field to the <strong>IBM</strong> SecureWay LDAP uniqueIdentifier field for a givenuser. You do not necessarily have to use the SecureWay LDAP uniqueIdentifierfield. However, you should ensure that the data type of the field selected iscapable of handling the specific value and the certificate attribute selected forauthentication is unique between certificates.Also ensure that <strong>WebSphere</strong> has the right to search such a field whenperforming authentication.Chapter 10. Administering <strong>WebSphere</strong> security 293

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!