13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

In this example, we have configured one login form page, login-itsobank. TheURI for our login form is /itsobank/login/login.html. This entry defines forWebSEAL the URI that should be intercepted. When a request is received forthis URI, WebSEAL will intercept the form, and will return to our ITSOBankapplication the GSO user ID and password defined for this Acess Manager userin the was50 GSO resource. If the user does not have a GSO ID and passworddefined for was50, then WebSEAL will return an error page to the user to informthem that they cannot login to the itsobank application.We now need to create a junction to our back-end <strong>WebSphere</strong> server, using the-S parameter. Once we have done this, Single Sign-On forms authentication willbe enable. The syntax of the junction command is:pdadmin> server task Webseald-WebSEALServer create -f -t tcp -p portnumber -h<strong>WebSphere</strong>ServerName -S path/filename.conf /JunctionNameWhere the following arguments are defined:► WebSEALServer is the host name of your WebSEAL server, for example:wsl01.► portnumber is the port number to connect to <strong>WebSphere</strong>, for example: 9443.►►►<strong>WebSphere</strong>ServerName is the host name of your <strong>WebSphere</strong> server, forexample: appsrv01.path/filename.conf is the full path and name of your configuration file.JunctionName is the name you with to assign to this junction, for example:/tai.After creating your junction, any request which causes the itsobank application topresent the login.html form will be intercepted by WebSEAL, and WebSEAL willprovide the users id and password back to the ITSOBank sample application.The end user will never be aware that a login to ITSOBank sample applicationwas performed on his behalf.12.4.3 Tivoli Access Manager plug-in for <strong>WebSphere</strong> Edge ServerThe <strong>WebSphere</strong> Edge Server is a collection of applications designed to improveWeb and application server performance and availability by load balancingservers, intelligently caching static content, and by moving content delivery asclose to the users, from a network perspective, as possible. The “edge of thenetwork” is normally the DMZ between an organization’s intranet and the publicInternet, and it is into this DMZ that the <strong>WebSphere</strong> Edge Server componentsare deployed.410 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!