13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Table 10-7 <strong>IBM</strong> SAS-specific sas.client.props configurationPropertycom.ibm.ssl.sas.outbound.keyStorecom.ibm.ssl.sas.outbound.keyStorePasswordcom.ibm.ssl.sas.outbound.keyStoreTypecom.ibm.ssl.sas.outbound.trustStorecom.ibm.ssl.sas.outbound.trustStorePasswordcom.ibm.ssl.sas.outbound.trustStoreTypecom.ibm.ssl.sas.outbound.protocolValueJKSJKSSSLv3Once SSL is configured, use the launchclient tool provided with <strong>WebSphere</strong> totest the connection. It may be feasible to run a packet monitoring tool to be surethat the information passing from client to server is, in fact, encrypted. Only theserver and client certificates should be sent in the clear and then only during theinitialization stage. In any case, these certificates are considered to be viewableby the public in general as they do not contain any private information.Should an error occur, the likelihood is that a Java exception trace will appear inthe client console. Often the errors refer to CORBA problems, CORBA being theunderlying marshalling mechanism with which the ORBs operate. Most CORBAexceptions are difficult to interpret due to their somewhat terse messages.Tracing can also provide a useful insight to the events that led up to the error.10.13 Connecting to directory servers (LDAP)This section will discuss the LDAP User Registry configuration for the<strong>WebSphere</strong> Application Server. The user registry we used to show theconfiguration steps is the <strong>IBM</strong> SecureWay Directory Server V3.2.2. This sectionwill show you how to configure your LDAP server for this sample, and how tocreate a sample user and a sample group entry in the directory. We provide anexample of how to configure <strong>WebSphere</strong> to use a given LDAP server over anormal LDAP connection, then use SSL for LDAP (LDAPS).For other LDAP servers, refer to Appendix B, “LDAP configurations” onpage 461.Chapter 10. Administering <strong>WebSphere</strong> security 317

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!