13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

correct. Then it trusts that the identity of the request is c_user, as specified inthe LTPA token.6. <strong>WebSphere</strong> sends output to WebSEAL.7. WebSEAL sends the output to the client. WebSEAL does not send the LTPAcookie to the client, but rather the cookie is stored in WebSEAL’s LTPA cache.This is advantageous since LTPA tokens, if sent to the client over the Internet,could be decrypted over time. Because the LTPA signature never changes,intercepting LTPA cookies and cracking LTPA tokens would be an easy andeffective way to breach an otherwise secure environment.Configuring an LTPA-enabled WebSEAL JunctionThe following procedure will describe the steps necessary to configure<strong>WebSphere</strong> to trust LTPA tokens that are issued by WebSEAL. This involvesgenerating an LTPA key file on the <strong>WebSphere</strong> server, copying the key file to theWebSEAL server, and using the key file when configuring the WebSEALjunction.1. On the <strong>WebSphere</strong> Administrative Console, click <strong>Security</strong> -> AuthenticationMechanisms -> LTPA to see the LTPA configuration panel, as shown inFigure 12-5.2. Change the password if necessary.Note: The first time that security is enabled with LTPA as theauthentication mechanism, LTPA keys are automatically generated withthe password entered in the panel. In this procedure, however, LTPA keyswill be generated manually so that they can be immediately exported andcopied to the WebSEAL server.3. Click the Generate Keys button.4. In the Key File Name field, enter the full path of a file on the <strong>WebSphere</strong>server where the key file should be placed.5. Click Export Keys to create the exported key file. The LTPA key file is a textfile which will look something like the one shown in Example 12-1.Example 12-1#<strong>IBM</strong> <strong>WebSphere</strong> Application Server key file#Thu Aug 15 14:28:47 EDT 2002com.ibm.Websphere.CreationDate=Thu Aug 15 14\:28\:47 EDT 2002com.ibm.Websphere.ltpa.version=1.0com.ibm.Websphere.ltpa.3DESKey=/VrD4i4I8XIiXK6AF/ELOiM9YRgH8IVdp7ji+BJPSDM\=com.ibm.Websphere.CreationHost=appsrv02388 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!