22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

176 Lotus Security Handbook<br />

The reverse proxy server must use cookies for authentication.<br />

Reverse proxy servers that rewrite URLs for authentication purposes are not<br />

supported. Some reverse proxy servers append authentication and session<br />

information to the end of URLs embedded in HTML that passes through the<br />

proxy back to the client. The client will include this appended data on subsequent<br />

requests to the reverse proxy server.<br />

When the reverse proxy server receives these subsequent requests from the<br />

client, the reverse proxy server strips the authentication data and rewrites the<br />

URL to accomplish the internal routing of requests. A Sametime server cannot<br />

operate behind a reverse proxy server that handles authentication data in this<br />

way.<br />

Reverse proxies that utilize cookies for authentication information must therefore<br />

be utilized. Additionally, the administrator should specify a lengthy time-out value<br />

for authentication cookies generated by the reverse proxy server. Setting a<br />

lengthy time-out value for authentication cookies can prevent unexpected user<br />

disconnections due to an authentication cookie expiration. Generally, the<br />

authentication cookie should be valid for the entire length of the longest meetings<br />

that are routinely conducted on the Sametime server deployed behind the<br />

reverse proxy server.<br />

5.5.3 Sametime limitations when using reverse proxy servers<br />

While Sametime 3.1 does support reverse proxy environments, there are some<br />

limitations to normal Sametime functionality.<br />

Client limitations and JVM requirements<br />

Not all Sametime clients can communicate with Sametime servers through a<br />

reverse proxy server. The following clients are supported:<br />

► Sametime Meeting Room and Sametime Broadcast clients<br />

The Sametime Meeting Room client and the Sametime Broadcast client can<br />

communicate with a Sametime server through a reverse proxy server when<br />

running with the following Web browsers and Java Virtual Machines (JVMs):<br />

– IE 6 browser + MS VM or Sun Microsystems JVM 1.4.1 + Java Plug-in).<br />

– Netscape 7 + Sun Microsystems JVM 1.4.1 (and associated Java Plug-in)<br />

► Sametime Connect for browsers (the Java version of Sametime Connect) and<br />

Sametime Links applications built with Sametime developer toolkits<br />

The Sametime Connect for browsers client and Sametime Links applications<br />

can communicate with a Sametime server through a reverse proxy server<br />

when running in an Internet Explorer 6 or Netscape 7 browser that operates<br />

with the Sun Microsystems JVM 1.4.1.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!