13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

►►Client certificate label: ClientKeyClient trust file: ClientTrustFile.jksExchange the certificates between the two parties, export the ServerKey fromthe ServerKeyFile.jks and import it into the ClientTrustFile.jks; export theClientKey from the ClientKeyFile.jks and import it into the ServerTrustFile.jks.10.12.2 Server side configurationThe Application Server must be configured to support SSL. An SSL configurationshould exist that describes the type of key stores used to establish the secureconnection and their location. Refer to 10.9.4, “Configuring <strong>WebSphere</strong> to use akey store” on page 276 for details on key stores.Note: The sas.server.props configuration file used in <strong>WebSphere</strong> ApplicationServer, version 4 is no longer used in version 5. However, the file remains inthe properties directory. The server security configuration is contained in a filecalled security.xml whose default location is/config/cells/BaseApplicationServerCell.Create a new SSL entry in the SSL Repertoire, following the steps in 10.8.1,“SSL configurations” on page 259 and using the following values for theattributes:►►►►►SSL alias: ORB SSLKey file: C:\<strong>WebSphere</strong>\Appserver\etc\ServerKeyFile.jksKey file password: passwordTrust file: C:\<strong>WebSphere</strong>\Appserver\etc\ServerTrustFile.jksTrust file password: passwordThe authentication protocol must be configured to use the correct SSL settings.1. Log in to the <strong>WebSphere</strong> Admin console, select <strong>Security</strong> -> AuthenticationProtocol -> CSIv2 Inbound Authentication.2. Ensure that Basic Authentication is supported, at the very least. It is also validto set Basic Authentication to Required.Note: When required is set to true for an attribute, where supported is also anoption, the supported attribute will not be used by the server.This is true for every attribute within CSI also.Chapter 10. Administering <strong>WebSphere</strong> security 311

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!