22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

not to have to rebuild this entire proxy setup utilizing the Tivoli WebSeal “proxy.”<br />

Thus, we would choose to install the Tivoli security plug-in for WebSphere Edge<br />

Server, also sometimes called WebSeal-Lite.<br />

So, our first steps, before we can integrate our existing environment, is to install<br />

a new Tivoli Access Manager server, followed by an installation of the<br />

WebSeal-Lite plug-in on our reverse proxy server. For details on installing and<br />

setting up Tivoli Access Manager, see the Tivoli Information Center at:<br />

http://publib.boulder.ibm.com/tividd/td/<strong>IBM</strong>AccessManagerfore-business4.1.html<br />

After we have Tivoli Access Manager installed, we must integrate it in our<br />

environment such that Tivoli Access Manager handles all authentication.<br />

14.6.2 Installing the WebSeal plug-in for Websphere Edge Server<br />

To install and configure the “WebSeal-Lite” plug-in on our reverse proxy server,<br />

we would perform the following:<br />

1. Install Tivoli Access Manager plug-in for Edge Server:<br />

a. Log into the system as a user with administrator privileges.<br />

b. Insert the <strong>IBM</strong> Tivoli Access Manager Web Security, Version 4.1 for<br />

Windows CD. Run the setup.exe file in the following location:<br />

cdrom_drive\windows\PolicyDirector\Disk Images\Disk1<br />

c. From the Select Packages window, select the plug-in for Edge Server<br />

package.<br />

2. Configure the plug-in for Edge Server:<br />

a. Run the wslconfig.exe program.<br />

b. When prompted, enter the following information:<br />

The port number for the Edge Server caching proxy. The default port<br />

number is 80.<br />

The Tivoli Access Manager administrative user ID and password as<br />

used when TAM was installed earlier. For example, enter sec_master<br />

and its associated password.<br />

This configuration utility actually completes the following tasks:<br />

► It creates registry objects for the server.<br />

► It adds the server to the security groups, ivacld-servers and SecurityGroup.<br />

► It creates an SSL certificate.<br />

► It obtains an SSL-signed certificate from the Tivoli Access Manager policy<br />

server.<br />

Chapter 14. Scenario implementation details 629

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!