13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

It follows that there are three ways of using the HTTP Basic Authentication (BA)headers to validate the WebEAL server and thereby trust its authentication of theclient’s identity:1. Send both a userID and password in the BA header. This would be configuredby doing the following:a. Configure the junction using -B -U ”tai_user” -W ”tai_pwd”b. Set the mutualSSL property to false.c. Do not define the loginID property.2. Send only a password in the BA header. This would be configured by doingthe following:a. Set the loginID property to a specical userID (e.g. tai_user).b. Add the password for tai_user to the basicauth-dummy-passwd variable inthe Webseald.conf file.c. Configure the junction using -b supply,or alternatively use -B -U”dummy_userID” -W ”tai_pwd”. The dummy_userID value in the BAheader will be ignored.3. Send nothing in the BA header. This would be configured b doping thefollowing:a. Set the mutualSSL property to trueb. Enable the junction to be a mutually authenticated SSL junction by using aclient certificate to authenticate WebSEAL to the back-end server.The following procedure details the steps necessary for creating a WebSEALjunction using Single Sign-On based on the Trust Association Interceptor. Theinterceptor will be configured to validate the request by authenticating a specialuserID and password supplied in the BA header by WebSEAL.Create a userid in the registry that the interceptor will use to validate the request.In this example we will assume the userid tai_user with passoword tai_pwd hasbeen created in the registry.Configure <strong>WebSphere</strong> to use TAIThe following steps will show, how to configure <strong>WebSphere</strong> to use TAI forauthentication.1. On the <strong>WebSphere</strong> Administrative Console, click <strong>Security</strong> -> AuthenticationMechanisms -> LTPA to view the LTPA configuration panel.2. Under Additional Properties, click Trust Association to see the TrustAssociation Panel shown in Figure 12-8Chapter 12. Tivoli Access Manager 395

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!