13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Enabling Single Sign-On for <strong>WebSphere</strong>After configuring <strong>WebSphere</strong> Application Server to use Domino LDAP, the SSOconfiguration is identical to the one discussed in the previous section. Pleaserefer to “Enabling Single Sign-On for <strong>WebSphere</strong>” on page 494 for details.Remember that you should always generate LTPA keys after successfulconfiguration of the LDAP user registry.Important: Do not forget to enter the domain name in the Single sign-onsection of the LTPA configuration panel.Enabling Single Sign-On for DominoWhen using Domino directory as a user registry, Domino Server does not need touse directory assistance as described in the previous section. After putting all theapplication users and groups into your Domino directory, you can follow theinstruction from “Enabling Single Sign-On for Domino” on page 499 for importingLTPA keys and enabling Single Sign-On for the Domino Server.For our sample scenario, we have defined the following users and groups inDomino Directory:Table C-2 Users and groups defined in Domino directory for ITSO applicationGroup namemanagergrp/ITSOclerkgrp/ITSOaccountantgrp/ITSOconsultantgrp/ITSOGroup membersmanager01/ITSOclerk01/ITSOaccountant01/ITSOconsultant01/ITSOWe have mapped Domino directory groups to corresponding user roles in theITSO bank application, and accordingly modified ACL in theITSOBankComments application database.If your server is already configured to use Single Sign-On, please remember thatreconfiguration does not mean creating a new Web Single Sign-On Configurationdocument. On a server, it may only be one Web Single Sign-On ConfigurationDocument. So, if you have one already, you should edit it and import new LTPAkeys.Testing Single Sign-OnFor testing this scenario you can follow testing instructions from the previoussection. Please refer to “Testing Single Sign-On” on page 505.512 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!