13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

1. Open the ikeyman tool that comes with <strong>WebSphere</strong>, able to handle the .jksfiles, then open the server trust store file; if you are using the dummykeystore, open the \etc\DummyServerTrustFile,jks.2. Import the LDAPSSLServer.arm as a signer certificate; use the file from theDomino server, you will have to copy the .arm file to your <strong>WebSphere</strong> servermachine.3. Close the ikeyman utility.To create a new SSL entry and configure <strong>WebSphere</strong> to use it to connect to theLDAP server, follow the steps from “Configuring the secure LDAP (LDAPS)connection” on page 328 using the following information.iPlanet Directory ServerIn this section, we will cover the steps required to configure <strong>WebSphere</strong> withNetscape’s iPlanet Directory Server <strong>V5.0</strong>. In this scenario, we have installedAccess Manager using the native installation method.Configuring <strong>WebSphere</strong> to use iPlanet Directory ServerIn order to configure <strong>WebSphere</strong>’s access to iPlanet Directory Server, we mustfirst define a user entry for <strong>WebSphere</strong> to use for binding to the directory, as wedid for <strong>IBM</strong> Directory Server.The only change we have made is that we are now using a directory suffix ofo=tamral,c=us instead of o=itso.After you have created your user entry, <strong>WebSphere</strong> is ready to be configured touse iPlanet Directory Server as its user registry.1. Start the <strong>WebSphere</strong> Administrator’s Console. Once you have started theconsole, log in and select <strong>Security</strong> -> User Registries -> LDAP. This willdisplay the LDAP User Registry panel.2. Fill out the LDAP configuration page as follows:– Server User ID: enter either the fully qualified Distinguished Name (DN) orthe <strong>WebSphere</strong> server ID user; we used the DN:cn=wasadmin,o=tamral,c=us.– Server User Password: enter the password for your user ID.– Type: Netscape.– Host: enter the fully qualified DNS name of your iPlanet Directory Server.In our configuration, our host name is tivoli9.svo.dfw.ibm.com.– Port: 389472 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!