29.01.2013 Views

WebSphere Application Server V7.0: Concepts ... - IBM Redbooks

WebSphere Application Server V7.0: Concepts ... - IBM Redbooks

WebSphere Application Server V7.0: Concepts ... - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

There are some specific considerations for installers that we address here. Take<br />

into account the following security considerations during the installation planning<br />

phase:<br />

► Certificates<br />

– If you will use digital certificates, make sure that you request them with<br />

enough lead time so that they are available when you need them.<br />

– If default certificates or dummy key ring files are provided with any of the<br />

products you plan to install, replace them with your own certificates.<br />

– If you are using self-signed certificates, plan your signer structure carefully<br />

and exchange signer certificates if necessary.<br />

Note: In <strong>WebSphere</strong> <strong>Application</strong> <strong>Server</strong> <strong>V7.0</strong> signer and personal<br />

certificates can be either created or imported during profile creation. If<br />

you have new certificates created you can choose the correct DN<br />

during profile creation.<br />

► Network and physical security<br />

– Usually one or more firewalls are part of the topology. After determining<br />

what ports need to be open, make a request to the firewall administrator to<br />

open them.<br />

– Plan the physical access to the data center where the machines are going<br />

to be installed to prevent delays to the personnel involved in the installation<br />

and configuration tasks.<br />

► User IDs<br />

– Request user IDs with enough authority for the installation purposes, for<br />

example, root on a Linux or UNIX operating system and a member of the<br />

administrator group on a Windows operating system. For more<br />

information, see the following Web page:<br />

http://publib.boulder.ibm.com/infocenter/wasinfo/v7r0/topic/com.i<br />

bm.websphere.installation.nd.doc/info/ae/ae/tins_install.html<br />

Although non-root installation is also supported, some limitations apply.<br />

For more information, see the following Web page:<br />

http://publib.boulder.ibm.com/infocenter/wasinfo/v7r0/topic/com.i<br />

bm.websphere.installation.nd.doc/info/ae/ae/cins_nonroot.html<br />

– If there is a policy on password expiration, it should be well known so as to<br />

avoid disruption on the service (password expiration of root, Administrator,<br />

or the password of the user to access some database).<br />

224 <strong>WebSphere</strong> <strong>Application</strong> <strong>Server</strong> <strong>V7.0</strong>: <strong>Concepts</strong>, Planning, and Design

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!