10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Authentication<br />

strength<br />

configuration<br />

To<br />

configure<br />

authentication<br />

strength<br />

levels,<br />

complete<br />

the<br />

instructions<br />

in<br />

each<br />

of<br />

the<br />

following<br />

sections:<br />

1.<br />

“Establish<br />

an<br />

authentication<br />

strength<br />

policy”<br />

2.<br />

Stop<br />

the<br />

<strong>WebSEAL</strong><br />

server.<br />

3.<br />

“Specify<br />

authentication<br />

levels”<br />

4.<br />

“Specify<br />

the<br />

authentication<br />

strength<br />

login<br />

<strong>for</strong>m”<br />

on<br />

page<br />

120<br />

5.<br />

Restart<br />

the<br />

<strong>WebSEAL</strong><br />

server.<br />

6.<br />

“Create<br />

a<br />

protected<br />

object<br />

policy”<br />

on<br />

page<br />

121<br />

7.<br />

“Specify<br />

network-based<br />

access<br />

restrictions”<br />

on<br />

page<br />

122<br />

8.<br />

“Attach<br />

a<br />

protected<br />

object<br />

policy<br />

to<br />

a<br />

protected<br />

resource”<br />

on<br />

page<br />

124<br />

9.<br />

“En<strong>for</strong>ce<br />

user<br />

identity<br />

match<br />

across<br />

authentication<br />

levels”<br />

on<br />

page<br />

125<br />

Establish<br />

an<br />

authentication<br />

strength<br />

policy<br />

This<br />

section<br />

consists<br />

of<br />

planning<br />

steps<br />

to<br />

be<br />

taken<br />

be<strong>for</strong>e<br />

specifying<br />

authentication<br />

strength<br />

settings<br />

in<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file.<br />

Complete<br />

the<br />

following<br />

steps:<br />

1.<br />

Compile<br />

a<br />

list<br />

of<br />

protected<br />

objects<br />

<strong>for</strong><br />

which<br />

access<br />

will<br />

be<br />

limited<br />

only<br />

to<br />

users<br />

who<br />

have<br />

successfully<br />

authenticated<br />

through<br />

a<br />

specific<br />

authentication<br />

method.<br />

For<br />

each<br />

protected<br />

object,<br />

specify<br />

the<br />

authentication<br />

method<br />

that<br />

applies.<br />

2.<br />

Compile<br />

a<br />

complete<br />

list<br />

of<br />

all<br />

authentication<br />

mechanisms<br />

that<br />

will<br />

be<br />

active<br />

(enabled)<br />

on<br />

the<br />

<strong>WebSEAL</strong><br />

server<br />

system.<br />

3.<br />

Determine<br />

a<br />

hierarchy<br />

(ranking)<br />

<strong>for</strong><br />

the<br />

active<br />

authentication<br />

mechanisms.<br />

Order<br />

the<br />

mechanisms<br />

from<br />

weakest<br />

to<br />

strongest.<br />

4.<br />

Determine<br />

if,<br />

during<br />

authentication<br />

strength<br />

level<br />

step-up,<br />

the<br />

user<br />

identity<br />

must<br />

be<br />

identical<br />

across<br />

the<br />

increased<br />

authentication<br />

level.<br />

5.<br />

Determine<br />

if<br />

any<br />

protected<br />

resources<br />

require<br />

access<br />

restriction<br />

based<br />

on<br />

the<br />

network<br />

address<br />

of<br />

the<br />

requesting<br />

client.<br />

Specify<br />

authentication<br />

levels<br />

Complete<br />

the<br />

following<br />

steps:<br />

1.<br />

Edit<br />

the<br />

[authentication-levels]<br />

stanza<br />

in<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file.<br />

For<br />

each<br />

authentication<br />

method<br />

to<br />

be<br />

used<br />

<strong>for</strong><br />

authentication<br />

level<br />

step-up,<br />

add<br />

an<br />

entry<br />

to<br />

the<br />

stanza.<br />

The<br />

supported<br />

authentication<br />

methods<br />

are<br />

described<br />

in<br />

the<br />

following<br />

table:<br />

Table<br />

19.<br />

Authentication<br />

methods<br />

supported<br />

<strong>for</strong><br />

authentication<br />

strength<br />

Authentication<br />

method<br />

Configuration<br />

file<br />

entry<br />

(none)<br />

level<br />

=<br />

unauthenticated<br />

Basic<br />

authentication<br />

Forms<br />

authentication<br />

level<br />

=<br />

password<br />

Token<br />

authentication<br />

level<br />

=<br />

token<br />

Certificate<br />

authentication<br />

level<br />

=<br />

certificate<br />

The<br />

default<br />

entries<br />

are:<br />

[authentication-levels]<br />

level<br />

=<br />

unauthenticated<br />

level<br />

=<br />

password<br />

Chapter<br />

5.<br />

<strong>WebSEAL</strong><br />

security<br />

policy<br />

119

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!