13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Property keycom.ibm.Websphere.security.Webseal.loginIDcom.ibm.Websphere.security.Webseal.mutualSSLValueThis property specifies the userID(e.g. tai_user in the scenarioabove) which will beauthenticated, using thepassword appearing in the HTTPBasic Authentication (BA) headerto validate the incommingrequest. If this property is used,the userID appearing in the BAheader is ignored. If this propertyis not used, the interceptorauthenticates using both theuserID and password appearingin the BA header. This propertyhas no effect when themutualSSL property is set to true.If this property is set to true, theWebSEAL interceptor implicitlytrusts that the WeEAL junctionhas been secured through theuse of one of WebSEAL’smutually authenticated SSLjunction capabilities. When thisproperty is set to true, theinterceptor skips theauthentication step in thevalidation of the request.Important: Setting the mutualSSL property to true effectively disables one ofthe mechanisms of validating the WebSEAL server and its authentication ofthe client’s identity. In some instances, it may be sufficient for the interceptor tovalidate the request on the basis of the originating hostname and port, but ingeneral this should be done with caution.Important: If the interceptor ignores or fails to validate a request, the<strong>WebSphere</strong> security runtime will proceed to handle the request as if theinterceptor had not been enabled. In other words, requests that are nothandled by the interceptor are not rejected, but rather are passed unchangedto the security runtime.394 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!