IBM Software __21. In the policy editor, click the Apply Policy button. __22. Click the Close Window link to close the policy editor. __23. Click the Apply button in the Multi-Protocol Gateway configuration page. __24. In the soapUI, click the green submit button to submit the request to your service. The request should now fail with an error message of “Rejected by policy.” To resolve this, you need to tell soapUI to include the WS-Security Usernametoken. __25. In soapUI, make sure the request tab is selected then click the Aut button to show the authentication settings. __26. Change the Outgoing WSS dropdown to be UsrtokenSignEncrypt. __27. Click the Aut button to close the authentication settings. __28. Click the green submit button to submit another request to the service. This time, the request should succeed. If you want to see the WS-Security UsernameToken that soapUI injected into the message, you can use the probe to inspect the transaction. __29. If you want to see the AAA policy reject a bad password, follow these steps: __a. In the soapUI request tab, click on the Aut button to show the authentication settings. __b. Select BadPassword_UNT from the Outgoing WSS dropdown – the password is incorrect for user david. __c. Click the Aut button to hide the authentication settings. __d. Click the green submit button to submit the request. The request should fail with the “Rejected by policy” message. __e. Restore the Outgoing WSS setting back to UsrtokenSignEncrypt and verify that the request succeeds (this is important for future labs). __30. If your configuration is working properly, you can click the Save Config link in the upper right part of the DataPower banner. This will save your configuration to the flash memory. 4.7 Summary In this lab, you saw how you can further secure your services with DataPower’s access control framework. You learned: ● Access Control Policies, also known as AAA policies, are a powerful and flexible way to prevent unauthorized access to your services. Through the point-and-click WebGUI, you can easily configure access policies to contact external authentication and policy servers. ● AAA policies can also do security mediation, such as converting between HTTP Basic Authentication and Kerberos/SPNEGO. AAA policies can also create a SAML assertion based on authenticated credentials extracted from the message. Page 72 WebSphere Lab Jam

