13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring <strong>WebSphere</strong> to use certificate mappingThe following steps will show you how to configure <strong>WebSphere</strong> ApplicationServer to use the certificate filter as required.1. Log in to the <strong>WebSphere</strong> Administration Console.2. Select <strong>Security</strong> -> User Registries -> LDAP.3. Select the Advanced LDAP Settings at the bottom of the LDAP page.4. Set the following fields in the Configuration panel:Certificate Map Mode: CERTIFICATE_FILTERCertificate Filter: uniqueIdentifier=${SubjectDN}5. Click OK, then save the configuration for <strong>WebSphere</strong>.6. You have to stop and start the application server to implement the advancedLDAP modifications.Configuring the directory server to use certifcate mappingThe directory server store in your user registry has to be updated to reflect thenew values to use certificate mapping. Basically the uniqueIdentifier field has tocontain the SubjectDN for each user; the SubjectDN value can be extracted fromthe public certificate of the user.In the following steps, we will use the <strong>IBM</strong> SecureWay LDAP Directory.1. Launch the SecureWay Directory Management Tool.2. Rebind as an Authenticated User with adequate privileges to modify usercredentials.3. Expand the directory tree and select the user entity against which you wish toauthenticate the personal client certificate. In this example, let us use theuser: manager.4. Click Edit, switch to the Other tab and find the uniqueIdentifier field.5. Enter the SubjectDN value for the uniqueIdentifier from the certificate. Usethe value returned by the Java keytool utility, in this case:EmailAddress=testwebclient@yahoo.com, CN=Thawte Freemail Member294 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!