10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

v<br />

token<br />

authentication<br />

v<br />

certificate<br />

authentication<br />

Authentication<br />

strength<br />

is<br />

supported<br />

over<br />

both<br />

HTTP<br />

and<br />

HTTPS,<br />

with<br />

the<br />

exception<br />

of<br />

certificate<br />

authentication.<br />

Since<br />

certificates<br />

are<br />

valid<br />

only<br />

over<br />

an<br />

SSL<br />

connection,<br />

it<br />

is<br />

not<br />

possible<br />

to<br />

step<br />

up<br />

to<br />

certificates<br />

over<br />

HTTP.<br />

If<br />

an<br />

object<br />

that<br />

requires<br />

certificate<br />

authentication<br />

is<br />

requested<br />

over<br />

HTTP,<br />

an<br />

error<br />

page<br />

will<br />

be<br />

served,<br />

as<br />

specified<br />

by<br />

the<br />

certstepup<br />

entry<br />

in<br />

the<br />

[acnt-mgt]<br />

stanza<br />

of<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file.<br />

Administrators<br />

apply<br />

the<br />

authentication<br />

levels<br />

to<br />

a<br />

protected<br />

resource<br />

by<br />

declaring<br />

and<br />

attaching<br />

a<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

protected<br />

object<br />

policy<br />

(POP)<br />

to<br />

the<br />

resource<br />

object.<br />

The<br />

POP<br />

is<br />

a<br />

standard<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

POP.<br />

Authentication<br />

strength<br />

policy<br />

is<br />

set<br />

and<br />

stored<br />

in<br />

a<br />

POP<br />

attribute<br />

called<br />

an<br />

IP<br />

Endpoint<br />

Authentication<br />

Method.<br />

The<br />

attribute<br />

takes<br />

an<br />

integer<br />

value<br />

that<br />

represents<br />

the<br />

authentication<br />

level.<br />

The<br />

lowest<br />

level,<br />

unauthenticated,<br />

is<br />

always<br />

0.<br />

Each<br />

level<br />

increases<br />

the<br />

integer<br />

index<br />

up<br />

to<br />

the<br />

total<br />

number<br />

of<br />

authentication<br />

methods<br />

that<br />

have<br />

been<br />

assigned<br />

a<br />

level.<br />

When<br />

clients<br />

first<br />

authenticate<br />

to<br />

<strong>WebSEAL</strong>,<br />

the<br />

authentication<br />

method<br />

used<br />

is<br />

stored<br />

as<br />

an<br />

extended<br />

attribute<br />

in<br />

the<br />

client’s<br />

credential.<br />

The<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

authorization<br />

service<br />

compares<br />

the<br />

authentication<br />

method<br />

(level)<br />

in<br />

the<br />

credential<br />

against<br />

the<br />

authentication<br />

level<br />

<strong>for</strong><br />

the<br />

requested<br />

resource,<br />

as<br />

specified<br />

in<br />

the<br />

POP.<br />

When<br />

the<br />

level<br />

in<br />

the<br />

POP<br />

exceeds<br />

the<br />

level<br />

in<br />

the<br />

credential,<br />

the<br />

user<br />

is<br />

prompted<br />

to<br />

increase<br />

the<br />

authentication<br />

strength<br />

level.<br />

The<br />

IP<br />

Endpoint<br />

Authentication<br />

Method<br />

attribute<br />

can<br />

also<br />

optionally<br />

be<br />

used<br />

to<br />

restrict<br />

access<br />

to<br />

a<br />

resource,<br />

based<br />

on<br />

the<br />

network<br />

address<br />

of<br />

the<br />

client<br />

that<br />

sent<br />

the<br />

access<br />

request.<br />

The<br />

access<br />

can<br />

be<br />

restricted<br />

based<br />

on<br />

an<br />

individual<br />

network<br />

(IP)<br />

address,<br />

or<br />

a<br />

range<br />

of<br />

network<br />

addresses.<br />

<strong>WebSEAL</strong><br />

uses<br />

the<br />

following<br />

algorithm<br />

to<br />

process<br />

the<br />

conditions<br />

in<br />

a<br />

POP:<br />

1.<br />

Check<br />

the<br />

IP<br />

endpoint<br />

authentication<br />

method<br />

policy<br />

on<br />

the<br />

POP.<br />

2.<br />

Check<br />

ACL<br />

permissions.<br />

3.<br />

Check<br />

time-of-day<br />

policy<br />

on<br />

the<br />

POP.<br />

4.<br />

Check<br />

the<br />

audit<br />

level<br />

policy<br />

on<br />

the<br />

POP.<br />

118<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!