13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Figure B-20 Cipher Preference panelSelect the SSL 3.0 tab, and verify that the cipher keys are selected as shownabove. Then click the OK button. The Encryption settings panel will then beredisplayed. The Allow client authentication radio button under ClientAuthentication is selected by default, which we accepted for our configuration.Once you have completed your configuration settings, click the Save button. Wehave now configured iPlanet Directory Server to allow SSL access.<strong>WebSphere</strong> SSL configurationWe are now ready to begin the configuration of <strong>WebSphere</strong> for SSL access toour iPlanet Directory Server. To begin, we must first set up the trust relationshipto our directory server. To do this, we are going to set up a new keystore file foruse by <strong>WebSphere</strong>. In this keystore, we are going to add the CA certificate fromthe CA that issued the server certificate for our iPlanet Directory Server as atrusted signer. When we do this, it means that for any certificate that <strong>WebSphere</strong>receives using this keystore, it will trust that certificate because it is signed by ourCA.Before proceeding, we need to obtain the public certificate from our CA.Depending on the CA you are using, the method will vary. In our case, we hadthe option to download the CA using a browser, and saved it on our <strong>WebSphere</strong>system. You will need to do the same before proceeding. Note that some CAswill give you an option as to what format to use when obtaining the certificate. Inthis case, request the Base64-encoded format.Appendix B. LDAP configurations 483

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!