13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Figure 11-6 presents the Runtime pattern for extended Single Sign-On solutionwhere heterogeneous application servers are used and an external securityserver provides security management for all application tiers.Outside WorldDemilitarized Zone(DMZ)Internal NetworkPublic KeyInfrastructureDirectory &<strong>Security</strong>ServerRegistrydataIP NetworkProtocol firewall<strong>Security</strong>ProxyDomain firewallApplicationServersApplicationServerClientExistingapplicationand dataExistingapplicationand dataClientTierSingle Sign-On Application 1<strong>Security</strong>IntegrationEnterpriseApplicationApplication 2Figure 11-6 Extended Single Sign-On runtime pattern for central security serviceNodes used in Figure 11-6 are:►►►<strong>Security</strong> Proxy: the role of the security proxy is to intercept incoming requestsand map or transform user credentials into the format acceptable to theapplication server that was the original target of the request. The securityproxy is used to implement Single Sign-On between heterogeneous Webapplication servers.Application Server: this node includes the application server that runs theapplication logic for the solution. It can be installed in the same machine withthe Web server or separated by a domain firewall as described in theSelf-Service runtime pattern.The Directory and <strong>Security</strong> Server provides the information about the usersand theirs rights for the application. The information may contain users’ IDs,passwords, certificates, access groups and so on. This node supplies the360 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!