13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

3. If you decide the use the <strong>IBM</strong> HTTP Server Administrative Console, log in tothe <strong>IBM</strong> HTTP Server Administrative Console as documented in 10.10.2,“Configuring the <strong>IBM</strong> HTTP Server” on page 281.4. Select <strong>Security</strong> -> Host Authorization from the left-side navigator.5. Click the Scope button, and select your virtual host from the list that appearsin a new window, in our case: .The new setting should appear next to the Scope button.6. Change the Mode of client authentication to use to Required.7. Submit the changes using the button at the bottom.8. Restart the Web server.Note: If you choose to edit the httpd.conf file manually, open it with yourfavorite browser from the \conf directory, then find the SSLconfiguration part. It should start with the definition of a new VirtualHost, forexample: . Find the SSLEnabledirective then insert the following directive:SSLClientAuth requiredSave the httpd.conf file, then close it and finally restart the Web server.9. <strong>WebSphere</strong> Application Server does not support the port 443 by default; youhave to modify the default host configuration. Log in to the <strong>WebSphere</strong>Administration Console, then select: Environment -> Virtual Hosts, thenclick Default host.10.Select Host aliases, click New, then provide the following values:Host Name: *Port: 443Click OK when you are finished.11.Save the configuration for <strong>WebSphere</strong>.12.You have to stop and restart the server to make the changes effective.Testing the client side certificateThe best way to test the client certificate is to use the Default Application thatships with <strong>WebSphere</strong> and use the snoop servlet by accessing it with your Webbrowser. Access the following address from the client:https:///snoop, to determine if your browser is correctlypassing a client certificate.296 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!