13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

[8/22/02 7:42:47:449 CDT] 277a2e5c Util < toString(array)[8/22/02 7:42:47:449 CDT] 277a2e5c ltpaLoginModu d cred token = [8/22/02 7:42:47:449 CDT] 277a2e5c ltpaLoginModu d Successfully gatheredauthentication information[8/22/02 7:42:47:449 CDT] 277a2e5c ltpaLoginModu d Using uid and password forauthentication[8/22/02 7:42:47:449 CDT] 277a2e5c ltpaLoginModu d Authenticating"null/tai_user"[8/22/02 7:42:47:449 CDT] 277a2e5c LTPAServerObj > authenticate[8/22/02 7:42:47:449 CDT] 277a2e5c LTPAServerObj < authenticate[8/22/02 7:42:47:449 CDT] 277a2e5c UserRegistryI > checkPassword[8/22/02 7:42:47:449 CDT] 277a2e5c LdapRegistryI > checkPassword[8/22/02 7:42:47:449 CDT] 277a2e5c LdapRegistryI d Authenticatingtai_user[8/22/02 7:42:47:450 CDT] 277a2e5c LdapRegistryI d Searching for users[8/22/02 7:42:47:450 CDT] 277a2e5c LdapRegistryI > getUserstai_user[8/22/02 7:42:47:450 CDT] 277a2e5c LdapRegistryI > search[8/22/02 7:42:47:450 CDT] 277a2e5c LdapRegistryI d DN: o=itso[8/22/02 7:42:47:450 CDT] 277a2e5c LdapRegistryI d Search scope: 2[8/22/02 7:42:47:450 CDT] 277a2e5c LdapRegistryI d Filter:(&(uid=tai_user)(objectclass=inetOrgPerson))...[[8/22/02 7:42:47:453 CDT] 277a2e5c LdapRegistryI d Found usercn=tai_user,o=itso[8/22/02 7:42:47:453 CDT] 277a2e5c LdapRegistryI > checkStopped[8/22/02 7:42:47:453 CDT] 277a2e5c LdapRegistryI < checkStopped[8/22/02 7:42:47:486 CDT] 277a2e5c LdapRegistryI d Time elapsed to open/closeDirContext: 33[8/22/02 7:42:47:486 CDT] 277a2e5c LdapRegistryI d Authenticated withcn=tai_user,o=itso[8/22/02 7:42:47:486 CDT] 277a2e5c LdapRegistryI < checkPasswordcn=tai_user,o=itso[8/22/02 7:42:47:486 CDT] 277a2e5c UserRegistryI d user cn=tai_user,o=itsopassword checks okIn this section of the trace, we see that TAI is processing the header informationprovided by our WebSEAL server, and is authenticating the WebSEAL server,using the user id and password provided with the -B option. If the id or passwordyou set in your junction is invalid, this will show up as an authentication error. Inthis example, the id passed to <strong>WebSphere</strong> is tai_user, and <strong>WebSphere</strong> was ableto successfully authenticate the WebSEAL server.In this final section of the trace, once <strong>WebSphere</strong> has authenticated ourWebSEAL server, the user identity passed by WebSEAL will be used for thisrequest. In our example, the user ID passed is manager. <strong>WebSphere</strong> will locatethe user ID passed in the user registry, and then use this identity to process the406 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!