09.12.2012 Views

Download PDF - IBM Redbooks

Download PDF - IBM Redbooks

Download PDF - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

for the specified security token type. For example, if you select Username<br />

as the token type, you have to select the UsernameTokenGenerator class<br />

as the token generator class.<br />

c. For the security token, expand the drop-down list and select the security<br />

token defined on the WS Extension page (BasicAuthToken).<br />

d. Select Use value type. Select the value type from the drop-down list that<br />

matches your selection. This selection fills the local name and callback<br />

handler. If you specify a token generator for a custom token, select<br />

Custom Token as the value type and enter the URI and local name<br />

manually. In our example, we select Username Token for basic<br />

authentication.<br />

e. Select the callback handler class or input your custom callback handler<br />

class name manually (for a custom token). Some provided callback<br />

handler classes can be selected from the list. The provided default<br />

callback handler classes are as follows:<br />

NonPromptCallbackHandler: Enter the user ID and password<br />

manually.<br />

GUIPromptCallbackHandler: Request the user ID and password by<br />

displaying a GUI prompt dialog box. This is useful for a J2EE<br />

application client.<br />

X590CallbackHandler: Get an X.509 certificate for a key store file.<br />

PkiPathCallbackHandler: Create an X.509 certificate and binary data<br />

without CRL using PKIPath encoding.<br />

PKCS7CallbackHandler: Create an X.509 certificate and binary data<br />

with or without CRL using PKCS#7 encoding.<br />

LTPATokenCallbackHandler: Get user credentials from the LTPA<br />

token.<br />

StdinPromptCallbackHandler: Prompt the user for a user ID and<br />

password on the command line.<br />

We select the NonPromptCallbackHandler for basic authentication. The<br />

user ID and password must be known in the server user registry.<br />

f. If the token generator is the NonPromptCallbackHandler, enter the user ID<br />

and password of the client. We use a user ID and password of WINSERV.<br />

g. If the selected callback handler requires a key store (for example, the<br />

X509CallbackHandler, PkiPathCallbackHandler, and<br />

PKCS7CallbackHandler), select Use key store and specify the key<br />

store-related information. You have to specify the key store storepass<br />

(password to access the key store), key store path, and key store type<br />

from the list.<br />

122 Security in WebSphere Application Server Version 6.1 and J2EE 1.4 on z/OS

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!