13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

The Edge Server Caching Proxy component can act as a reverse proxy, verysimilar to the WebSEAL reverse proxy (which, incidently, also does documentcaching). Also similar to the WebSEAL reverse proxy, the Edge Server CachingProxy can be made to authenticate and authorize users against a Tivoli AccessManager security domain via the Tivoli Access Manager Plug-in for Edge Server.The Plug-in for Edge Server incorporates an Access Manager runtime into theCaching Proxy, which allows the proxy to perform authentication andauthorization based on ACLs and POPs in the Access Manager Object Space.Because the authenticating reverse proxy functionality provided by WebSEAL ismore feature-rich than that provided by the Tivoil Access Manager Plug-in forEdge Server, and because WebSEAL provides similar load balancing andcontent caching functions to the Edge Server, using WebSEAL is the preferredway to incorporate Tivoli Access Manager based security into the DMZ.However, the Tivoli Access Manager Plug-in for Edge Server provides an easyway to integrate Tivoli Access Manager based security into any existinginfrastructure which features an Edge Server caching proxy. In addition, the EdgeServer’s caching proxy provides a much more flexible set of caching options thandoes WebSEAL.The following sections compare the security related aspects of the Tivoli AccessManager Plug-in for Edge Server with WebSEAL.Access ControlIn WebSEAL, as described previously, access control can be assigned at thejunction level. Additionally, if more finely grained access control is needed, it canbe signed to objects below the junction. The query_contents command is usedwith pdadmin to create these objects in the Access Manager Object Space.When using the Plug-in for Edge Server, there is no junction object. Instead,access control is always applied directly to the objects which represent theserver’s content. Here also, the query_contents command is used, this time inconjunction with the wesosm command to create these objects in the AccessManager Object Space.User Login MethodsWebSEAL provides a complete set of standard user login methods, andadditonal methods are supported through customization.The Plug-in for Edge Server is limited to Basic, Forms-based, andCertificatie-based authentication methodsSingle Sign-On to <strong>WebSphere</strong> ApplicationsWebSeal supports Single Sign-On to <strong>WebSphere</strong> Applications via the followingmechanisms:Chapter 12. Tivoli Access Manager 411

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!