13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

This method allows the developer to control the authentication process. Bydefault, the values that the end user supplies in the form are transmitted inclear text as parameter values in the HTTP request. To secure the userinformation during transmission, the connection should be encrypted.The Application Assembly Tool has an option for digest authentication, but thisoption is not supported by <strong>WebSphere</strong> at the moment. If a security constraint hasbeen set but no authentication method for a Web module has been configured,the default is to use basic authentication.To set up an authentication method for a Web application:1. Load your Web application module into the Application Assembly Tool, in ourexample: itsobank.ear.2. Click itsobank -> Web Modules to expand the tree.3. Right-click the itsobankWeb Module and from the pop-up menu selectProperties.4. Select the Advanced tab.5. Select the Login Configuration checkbox, select appropriate authenticationmethod and provide the Realm name that will be used by the Web serverduring authentication.6. Click OK to approve the changes.Chapter 4. Securing Web components 47

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!