29.01.2013 Views

WebSphere Application Server V7.0: Concepts ... - IBM Redbooks

WebSphere Application Server V7.0: Concepts ... - IBM Redbooks

WebSphere Application Server V7.0: Concepts ... - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Further advantages of using Tivoli Access Manager<br />

We already reviewed the enterprise level advantages of using Tivoli Access<br />

Manager. Using Tivoli Access Manager at the application server level has the<br />

following further advantages:<br />

► Supports accounts and password policies<br />

► Supports dynamic changes to the authorization table without having to restart<br />

applications<br />

► Provides tight integration with <strong>WebSphere</strong> <strong>Application</strong> <strong>Server</strong><br />

Security, networking, and topology considerations<br />

Because the LDAP server contains, and the Access Manager server manages,<br />

sensitive data in terms of authentication, authorization, and privacy, the servers<br />

belong to the data layer of the network. It is suggested to enable Secure Sockets<br />

Layer (SSL) configuration options between the databases so data is encrypted.<br />

Legal considerations (privacy and data protection): Be aware that there<br />

might be some legal or regulatory issues that surround storing of certain data<br />

types, such as personally identifiable data in the European Union, on IT<br />

systems. Ensure that you have consulted your legal department before<br />

deploying such information on your systems. These considerations vary by<br />

geography and industry.<br />

2.2 Tivoli Directory <strong>Server</strong><br />

In today's highly connected world, directory servers are the foundation of<br />

authentication systems for internal, and more commonly, external user<br />

populations in the corporate infrastructure.<br />

<strong>IBM</strong> Tivoli Directory <strong>Server</strong> provides a high-performance Lightweight Directory<br />

Access Protocol (LDAP) identity infrastructure capable of handling millions of<br />

entries. It is built to serve as the identity data foundation for your Web<br />

applications and identity management initiatives.<br />

2.2.1 Lightweight Directory Access Protocol<br />

A directory is a data structure that enables the look up of names and associated<br />

attributes arranged in a hierarchical tree structure. In the context of enterprise<br />

application servers, this enables applications to look up a user principal and<br />

determine what attributes the user has and of which groups the user is a<br />

member. Decisions about authentication and authorization can then be made<br />

using this information.<br />

Chapter 2. Integration with other products 33

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!