13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

user’s browser and serves the requested resource (theCustomerTransfer.html page in case of <strong>WebSphere</strong> ITSOBank application).7. Once the user is authenticated and the cookie is available, that user canrequest another protected resource from Domino or <strong>WebSphere</strong>.8. Domino/<strong>WebSphere</strong> validate the token provided for the user and tell the Webserver to send the requested resource to the browser, as long as the user hasproper access to that resource, without prompting again with the challengeinformation.Log in with DominoThe following steps will describe the Single Sign-On process between Dominoand <strong>WebSphere</strong>, when the user logs in to Domino first.1. A Web user submits a request to the Web server (Domino) for a protectedresource, to create a new Comment document in the ITSOBankCommentsApplication database.2. Domino prompts the user for the authentication information.3. The user responds by supplying the information (user name and password orcertificate).4. Domino then verifies the authentication information in the Domino directory,checks whether the user has rights to access to database and issues anLTPA token for the user as an HTTP cookie, which is stored in the user’sbrowser. It then serves the requested resource (it opens the new Commentdocument).5. Once the user is authenticated and the cookie is available, that user canrequest another protected resource from Domino/<strong>WebSphere</strong>.6. Domino/<strong>WebSphere</strong> validate the token provided for the user and tell the Webserver to send the requested resource to the browser, as long as the user hasproper access to that resource, without prompting again with the challengeinformation.The necessary steps to set up Single Sign-On between <strong>WebSphere</strong> and Dominoinvolve:►►►Configuring <strong>WebSphere</strong> to use Domino LDAPEnabling Single Sign-On for the <strong>WebSphere</strong> Application ServerEnabling Single Sign-On for the Domino ServerConfiguring <strong>WebSphere</strong> LDAPFor the detailed configuration information, refer to “Lotus Domino” on page 462and follow the instructions from there.Appendix C. Single Sign-On with Lotus Domino 511

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!