11.07.2015 Views

Borland VisiBroker® 7.0 - Borland Technical Publications

Borland VisiBroker® 7.0 - Borland Technical Publications

Borland VisiBroker® 7.0 - Borland Technical Publications

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Security Properties for JavaProperty Description Defaultvbroker.security.trustpointsRepositoryvbroker.security.defaultJSSETrustvbroker.security.assertions.trust.Specifies a path to the directory containing trustedcertificates and CRLs or to a trusted Keystore whose valuesare implementations of TrustedCertificateEntry. Defaultvalues are either a directory, given in the formatDirectory: or a Keystore, given in the formatKeystore:.If set to true, the JSSE default trust files like cacerts andjssecacerts, if present in JRE, will be used to load trustedcertificates.This property is used to specify a list of trusted roles(specified with the format @). is a uniquely identified for each trust assertion rule as a list ofdigits.For example, settingvbroker.security.assertions.trust.1=ServerAdmin@defaultmeans this process trusts any assertion made by theServerAdmin role in the default authorization domain.vbroker.security.assertions.trust.all Setting to true will trust all the assertion made by peers. falsevbroker.security.server.requireUPIdentity Set this to true if the server requires the client to send aUsername/Password for authentication (regardless ofcertificate-based authentication). This is a server-sideproperty.n/avbroker.security.cipherListvbroker.security.controlAdminAccessvbroker.security.serverManager.authDomainvbroker.security.serverManager.role.allvbroker.security.serverManager.role.vbroker.security.support.gatekeeper.replyForSASvbroker.security.domain..defaultAccessRulevbroker.se.iiop_tp.scm.ssl.listener.trustInClientvbroker.security.wallet.typevbroker.security.wallet.identityvbroker.security.wallet.passwordSet this to a list of comma-separated ciphers to be enabledby default on startup. If not set, a default list of ciphersuiteswill be enabled. These should be valid SSL Ciphers.Set this to true for enabling Server Manager operations on aSecure Server.Points to a security domain listed invbroker.security.authDomains. The specified domain is usedfor the Server Manager's role-based access control checks.A rolemap must be specified for the domain.Specifies the role name required for accessing all ServerManager operations.Specifies the role name required for accessing the specifiedmethod of the Server Manager.This property is used with GateKeeper with security enabled.When set to true, the username and password will not bedelegated to the backend server for authentication.Specifies whether to grant or deny access to the domain bydefault in the absence of security roles for the provideddomain. Acceptable values are grant or deny.A server side property. Set to true to have the server requirecertificates from the client. These certificates must also betrusted by the server by setting the appropriate server-sidetrust properties. For more information, see thevbroker.security.trustpointsRepository property and thevbroker.security.defaultJSSETrust property.A wallet is a set of directories containing encrypted privatekeys and certificate chains for each identity. Use thisproperty to point to the directory containing the directories forall identities, using the format: Directory:Use to point to a directory within the path defined invbroker.security.wallet.type that contains keys and/orcertificate information for a specific identity. Note that thevalue of this property must consist only of lower-case letters.Specifies the password used to decrypt the private key or thepassword associated with the login.n/afalsen/an/afalsen/an/an/afalsegrantfalsen/an/an/aChapter 9: Security Properties for Java 89

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!