13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

►►►WebSEAL can forward modified or unmodified HTTP Basic Authentication(BA) headers to <strong>WebSphere</strong>. WebSEAL can also forward new headers basedon Global Sign-on (GSO) user mapping.<strong>WebSphere</strong> can be made to trust the authentication performed by WebSEALthrough the use of TAI or LTPA.When the application requires forms-based authentication, WebSEAL cansubmit the authentication form on behalf of the user.In contrast:► The Plug-in for Edge Server also supports Single Sign-On via HTTP BasicAuthentication headers, however with a more limited set of filtering options.Global Sign-on usename mapping is not supported.►►The Plug-in for Edge Server supports trust relationships using LTPA cookies.TAI is not supported.Forms-based Single Sign-On is not supported by the Plug-in for Edge Server.In summary, WebSEAL provides a more flexible and customizable layer ofsecurity to a <strong>WebSphere</strong> environment, when compared to the Edge ServerCaching Proxy configured with the Access Manager Plug-in for Edge Server. Insome cases, this may be outweighed by the more flexible caching capabiliteis ofthe Edge Server Caching Proxy.For more information on the Access Manager Plug-in for Edge Server, see thefollowing documents:► <strong>IBM</strong> <strong>WebSphere</strong> Edge Server: New Features and Functions in Version 2,SG24-6511-00.►Plug-in for Edge Server User’s Guide, GC23-4685-00.12.5 Scenario 2: Protecting Web resourcesThis scenario shows the different techniques to protect Web resources in<strong>WebSphere</strong> using the Tivoli Access Manager.12.5.1 Tivoli WebSEALWebSEAL is Access Manager’s authentication engine. It is a multi-threaded Webserver capable of applying security policy through Access Control Lists, ACLs, toURLs and servlets on junctioned Web servers within Access Manager'sprotected Web object space. WebSEAL is also where Access Manager providesSingle Sign-On solutions and it is an integral part of the “defense in depth”strategy when used in its role as a reverse proxy server.412 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!