22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

summarized here; it is recommended that the related product documentation be<br />

consulted to obtain more detailed steps. The steps that are unique to<br />

WebSphere Portal are described here in detail. After completing these steps, all<br />

requests, starting with the portal login, are encrypted.<br />

First, it is necessary to configure the Web server to support HTTPS. If this is a<br />

production environment, you need to obtain a certificate from a Certificate<br />

Authority (CA). For testing purposes, it is possible to use IKEYMAN to generate a<br />

self-signed certificate.<br />

In configurations where the Web server and portal server reside on separate<br />

machines, requests that enter the Web server have to be rerouted to the<br />

application server. Under these circumstances, you must also configure SSL<br />

between the Web server and the application server to provide more complete<br />

security. This requires that another keyfile be created for the Web server plug-in<br />

and another keyfile using ikeyman be provided for the embedded HTTPD of the<br />

WebSphere Application Server.<br />

For complete instructions for this step, refer to “Configuring SSL between Web<br />

server and WebSphere Application Server” in the <strong>IBM</strong> Redbook, <strong>IBM</strong><br />

WebSphere V4.0 Advanced Edition Security, SG24-6520.<br />

12.5.3 Changing passwords<br />

Passwords provide an additional level of security in the portal environment. Any<br />

default passwords that are accepted during installation must be changed<br />

immediately to ensure security.<br />

If Setup Manager is used to create users, such as the DB2 database<br />

administrator, the passwords for those user IDs are configured to expire in 42<br />

days. The passwords should be changed after the installation has been<br />

completed.<br />

During installation, Setup Manager allows the selection of a user ID and<br />

password to be selected for the portal administrator. If the default portal<br />

administrator user ID and password assigned by Setup Manager is accepted, it is<br />

important that both the wpsbind and wpsadmin passwords be changed in the<br />

Administrative Console to prevent unauthorized access to WebSphere Portal<br />

Server.<br />

Chapter 12. Security features of other Lotus products 567

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!