13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

3. <strong>WebSphere</strong> will validate your entries and display the Global <strong>Security</strong> page.Enable global security.4. Scroll down the Configuration panel and select LDAP for the Active UserRegistry selection.5. Click the OK button. Once <strong>WebSphere</strong> validates your configuration, andreturns with no errors, save your current configuration. You will then need tostop and restart your <strong>WebSphere</strong> server before proceeding.Once you have restarted your <strong>WebSphere</strong> server, open the <strong>WebSphere</strong>Administrative Console in your browser. You will now see that, in addition to auser ID field, a Password field is displayed. To log in, use a valid user ID andpassword. You have now successfully configured <strong>WebSphere</strong> to use theNetScape iPlanet Directory Server as its user registry.Note: In our case, we used the user ID and password we defined for theServer User ID on the LDAP User Registry’s panel . Under the <strong>Security</strong>Center, you can select Manage Console Users to define additional user IDs,however, they must first be defined in your directory server.Configuring <strong>WebSphere</strong> SSL access to iPlanet Director ServerNow that we have configured <strong>WebSphere</strong>, we will proceed, as we did with the<strong>IBM</strong> Directory Server, to secure our connection using SSL. As with the <strong>IBM</strong>Directory Server scenario, we need to establish a trusted relationship between<strong>WebSphere</strong> and our iPlanet Directory Server. Unlike <strong>IBM</strong> Directory Server,however, the iPlanet Directory Server does not allow us to generate a self-signedkey for use with its server. We will have to obtain a server certificate from aCertificate Authority (CA). In our scenario, we used our own CA to generate thecertificates being used. In your environment, you may well be using acommercial CA to accomplish this task. Regardless, the steps are basically thesame; only the details as to how to obtain your certificate and your root CAcertificate will differ.Obtaining a server certificate for iPlanet Directory ServerIn order to obtain a digital certificate for our iPlanet Server, we must first build acertificate request to send to a CA. This certificate request will contain theidentity information of our iPlanet Directory Server, as well as the public key forthe corresponding private key that the Directory Server will generate for ourrequest. The process of obtaining a certificate from our CA is what establishestrust; the CA will verify by some means the identity of the requestor for acertificate, and will sign the certificate, establishing its authenticity. Thereafter,any entity which receives the certificate, can, by virtue of the signing CA,establish that the certificate is indeed valid, presuming of course that therecipient also trusts the signing CA.474 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!