13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The Policy Server replicates this database to all the local authorization servers,including WebSEAL, throughout the domain, publishing updates as required. ThePolicy Server also maintains location information about the other AccessManager and non-Access Manager servers operating in the secure domain.There can be only one Policy Server active within a domain.Access Manager provides C and Java authorization APIs which can be usedprogrammatically within other applications and clients. Client calls forauthorization decisions, through the Access Manager Run-time service, whichmust be on every server participating in the secure domain, are always referredto an Authorization Server. Programatically made calls can be local or remote;they will be passed to an Authorization Server. When running local node API, theapplication communicates to the security server (Access Manager), noauthorization server is required.Authorization servers are the decision-making servers that determines a client'sability to access a protected resource based on the security policy. Each serverhas a local replica of the policy database. There must be at least one within aSecure Domain.Web Portal Manager, a <strong>WebSphere</strong>-hosted application is provided to enter andmodify the contents of the policy store and the user registry. There is also acommand line utility, pdadmin, which extends the available commands availableto include the creation and registration of authentication blades such asWebSEAL which will be described a little later.Access Manager can be configured to integrate with many of the <strong>WebSphere</strong>branded products and ships with explicit plug-ins for the following products:►►►<strong>WebSphere</strong> Application Server.<strong>WebSphere</strong> Edge ServerBEA Robotic Application Server► Web Server Plug-in, which supports IIS 5.0 for a Windows 2000Server/Advanced Server environment, iPlanet 6.0 for Solaris OperatingEnvironment 7 (sparc) and IHS 1.3.19 for an AIX 5L environment.The list of point products and components shipped in the Tivoli Access ManagerV3.9 package can be found in Table 12-1 on page 377.376 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!