22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

570 Lotus Security Handbook<br />

Authentication<br />

Member Services must access the user's authentication and registry group<br />

information from the Authentication component. The authentication registry<br />

refers to the data store for user authentication data and registry groups. Group<br />

information used to configure authorization is considered privileged information,<br />

and the groups are registry groups.<br />

Typically, the authentication registry is LDAP or a database. However, the<br />

authentication registry can be a custom data store that is unknown to Member<br />

Services. Member Services does not support a Local Operating System as the<br />

authentication registry. The authentication registry is specified in WebSphere<br />

Portal Server during installation and is recorded in the following XML file:<br />

/lib/app/wms.xml<br />

WebSphere Portal Server always uses WebSphere Application Server for<br />

authentication. However, WebSphere Application Server must be configured to<br />

communicate with the appropriate registry type.<br />

Changing Member Services password<br />

If the database or LDAP password is changed after installation, it is also<br />

necessary to change the Member Services password so that it can continue to<br />

access the user registry. An encrypted password must be generated and must<br />

replace the encrypted passwords.<br />

Configuring Member Services<br />

During installation, Portal Server generates the configuration parameters for<br />

Member Services and stores them in the following XML file:<br />

/lib/app/xml/wms.xml<br />

It is possible to manually edit this file to modify the initial configuration settings.<br />

The Portal Server repository consists of either one or two data sources: a<br />

standalone database, or a combination of a database and a directory server.<br />

This directory server might be accessible only through some CustomRegistry.<br />

The configuration of the data sources is contained in the following XML file:<br />

/lib/app/xml/wms.xml<br />

Mapping of user profile attributes to LDAP object classes is defined in the<br />

following XML file:<br />

/wms/xml/attributeMap.xml<br />

These files specify the names of the various data repositories, their<br />

implementation classes, and the mapping between attributes in the user object

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!