10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

When<br />

client-notify-tod<br />

=<br />

yes,<br />

<strong>WebSEAL</strong><br />

sends<br />

the<br />

client<br />

an<br />

error<br />

message<br />

stating<br />

that<br />

the<br />

authorization<br />

failure<br />

was<br />

due<br />

to<br />

a<br />

failed<br />

time-of-day<br />

#<br />

POP<br />

access<br />

check.<br />

This<br />

entry<br />

is<br />

set<br />

to<br />

no<br />

by<br />

default.<br />

Specifying<br />

error<br />

page<br />

location<br />

To<br />

specify<br />

the<br />

directory<br />

location<br />

<strong>for</strong><br />

the<br />

error<br />

pages,<br />

set<br />

the<br />

error-dir<br />

entry<br />

in<br />

the<br />

[content]<br />

stanza:<br />

[content]<br />

error-dir<br />

=<br />

lib/errors<br />

The<br />

value<br />

lib/errors<br />

is<br />

the<br />

default<br />

directory.<br />

You<br />

can<br />

modify<br />

this<br />

value.<br />

This<br />

location<br />

is<br />

relative<br />

to<br />

the<br />

directory<br />

specified<br />

by<br />

the<br />

server-root<br />

entry<br />

in<br />

the<br />

[server]<br />

stanza.<br />

In<br />

addition,<br />

the<br />

directory<br />

specific<br />

to<br />

your<br />

locale<br />

is<br />

automatically<br />

appended<br />

to<br />

the<br />

end<br />

of<br />

the<br />

directory<br />

hierarchy.<br />

For<br />

example,<br />

given<br />

a<br />

system<br />

with<br />

the<br />

instance<br />

name<br />

webseal1,<br />

and<br />

the<br />

following<br />

configuration<br />

settings:<br />

v<br />

server-root<br />

=<br />

/opt/pdweb/www-webseal1<br />

v<br />

error-dir<br />

=<br />

lib/errors<br />

v<br />

English<br />

locale<br />

directory<br />

of<br />

C<br />

the<br />

location<br />

of<br />

the<br />

error<br />

pages<br />

would<br />

be:<br />

/opt/pdweb/www-webseal1/lib/errors/C<br />

Backwards<br />

compatibility<br />

v<br />

<strong>WebSEAL</strong><br />

Version<br />

5.1<br />

introduced<br />

the<br />

following<br />

new<br />

error<br />

pages:<br />

–<br />

38cf04d7.html<br />

–<br />

38cf04c6.html<br />

These<br />

messages<br />

provide<br />

in<strong>for</strong>mation<br />

indicating<br />

that<br />

the<br />

encountered<br />

failure<br />

originated<br />

with<br />

a<br />

backend<br />

server,<br />

not<br />

with<br />

<strong>WebSEAL</strong>.<br />

In<br />

past<br />

releases,<br />

<strong>WebSEAL</strong><br />

returned<br />

the<br />

default<br />

error<br />

page<br />

only.<br />

If<br />

you<br />

want<br />

to<br />

retain<br />

the<br />

previous<br />

behavior,<br />

remove<br />

the<br />

new<br />

HTTP<br />

error<br />

message<br />

pages<br />

from<br />

the<br />

error<br />

message<br />

page<br />

directory.<br />

v<br />

<strong>WebSEAL</strong><br />

Version<br />

5.1<br />

introduced<br />

a<br />

new<br />

HTTP<br />

error<br />

message<br />

<strong>for</strong><br />

use<br />

when<br />

access<br />

is<br />

denied<br />

because<br />

a<br />

protected<br />

object<br />

policy<br />

(POP)<br />

time<br />

of<br />

day<br />

policy<br />

was<br />

not<br />

satisfied.<br />

Use<br />

of<br />

this<br />

error<br />

message<br />

page<br />

is<br />

controlled<br />

by<br />

a<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

setting.<br />

To<br />

disable<br />

use<br />

of<br />

this<br />

page,<br />

change<br />

the<br />

following<br />

configuration<br />

setting:<br />

[acnt-mgmt]<br />

client-notify-tod<br />

=<br />

no<br />

Note:<br />

A<br />

403<br />

is<br />

always<br />

logged,<br />

regardless<br />

of<br />

the<br />

value<br />

assigned<br />

to<br />

client-notify-tod.<br />

Chapter<br />

3.<br />

<strong>WebSEAL</strong><br />

server<br />

administration<br />

87

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!