22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

630 Lotus Security Handbook<br />

► It configures the Edge Server caching proxy to use the plug-in for Edge<br />

Server by setting directives in the Edge Server caching proxy configuration<br />

file, ibmproxy.conf.<br />

► It restarts the Edge Server caching proxy process, ibmproxy.<br />

Next, the configuration utility starts the plug-in for Edge Server object space<br />

manager utility, by using the wesosm command. This utility updates the Tivoli<br />

Access Manager object space to create a new object space container for the<br />

plug-in for Edge Server.<br />

Configuration of the plug-in for Edge Server is then complete. The Edge Server<br />

caching proxy should be running with the plug-in for Edge Server loaded. The<br />

administrative user, sec_master, can be used to access the caching proxy’s<br />

home page.<br />

14.6.3 Integrating Domino-based servers with TAM<br />

To integrate the Lotus Domino-based services (Domino, Sametime, QuickPlace,<br />

and so forth) so that the SSO LTPA cookie can continue to be passed to Domino<br />

for single sign-on, a junction must be created from the <strong>IBM</strong> Tivoli WebSeal<br />

plug-in on the reverse proxy server to the backend Domino servers. This is done<br />

with the following steps:<br />

1. Open the Administration Command Prompt (PDAdmin) from the<br />

AccessManager for e-business program group in the Start menu.<br />

2. Log in as pdadmin.<br />

3. Create a junction to the Lotus Domino server using the following arguments.<br />

– Type of connection (-t)<br />

– Backend host (-h)<br />

– TCP port number backend host is bound to (-p)<br />

– Specify Single Sign On (-A)<br />

– The key file (-F)<br />

– Key password (-Z)<br />

– Ensure JavaScript is filtered correctly (-j)<br />

– Provide the junction name (/)<br />

Example 14-2 Creating a WebSeal junction to Domino<br />

commands:<br />

pdadmin>login<br />

Enter User ID:sec_master<br />

Enter Password:

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!