13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Testing the secure connectionTo test the secure connection, use your favorite Web browser and access a Webapplication on <strong>WebSphere</strong> Application Server using port 9080, for example:https://wassrv01.itso.ibm.com:9080/itsobankMake sure you use the https protocol, if not, the returned page will look like this:Figure 10-45 False HTTP responseIn order to test the secure connection when client side certification is required,the right certificate with public and private key has to be imported into thebrowser.1. On the Web server machine, launch the ikeyman utility that can handle theCMS key database file.2. Open the keyfile for the plugin, in our example:c:\<strong>IBM</strong>HttpServer\conf\keys\WASplugin.kdb. Provide the password whenprompted.3. Selec the WASplugin certificate under the Personal Certificates, then clickExport.4. Save the certificate in PKCS12 format to a file,c:\<strong>IBM</strong>HttpServer\conf\keys\WASplugin.p12. Provide a password to securethe PKCS12 certificate file, then in the next panel select Weak encryption(browser compatible).5. Close the keyfile and quit ikeyman when you are done.6. Copy the saved WASplugin.p12 file to the client machine from which you wantto access the <strong>WebSphere</strong> server.7. Import the PKCS12 file into your favorite browser. In Microsoft InternetExplorer, select Tools -> Internet Options... from the menu. Switch to theContent tab then click Certificates. Import the WASplugin.p12 certificate byusing the Import... button; provide the password for the file where necessary.Chapter 10. Administering <strong>WebSphere</strong> security 309

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!