10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

The<br />

entry<br />

level<br />

=<br />

unauthenticated<br />

must<br />

always<br />

be<br />

the<br />

first<br />

in<br />

the<br />

list.<br />

Additional<br />

entries<br />

can<br />

be<br />

placed<br />

in<br />

any<br />

order.<br />

For<br />

example,<br />

to<br />

enable<br />

authentication<br />

strength<br />

levels<br />

<strong>for</strong><br />

certificate<br />

authentication<br />

at<br />

the<br />

highest<br />

level,<br />

the<br />

completed<br />

stanza<br />

entry<br />

would<br />

be:<br />

[authentication-levels]<br />

level<br />

=<br />

unauthenticated<br />

level<br />

=<br />

password<br />

level<br />

=<br />

certificate<br />

Note:<br />

There<br />

should<br />

be<br />

only<br />

one<br />

entry<br />

<strong>for</strong><br />

each<br />

authentication<br />

mechanism.<br />

2.<br />

Verify<br />

that<br />

each<br />

authentication<br />

method<br />

listed<br />

in<br />

[authentication-levels]<br />

is<br />

enabled.<br />

To<br />

determine<br />

if<br />

an<br />

authentication<br />

method<br />

is<br />

enabled,<br />

check<br />

the<br />

appropriate<br />

entries<br />

in<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file.<br />

To<br />

review<br />

the<br />

necessary<br />

entries<br />

and<br />

access<br />

the<br />

authentication<br />

configuration<br />

instructions,<br />

see<br />

the<br />

following<br />

sections:<br />

v<br />

“Enabling<br />

and<br />

disabling<br />

basic<br />

authentication”<br />

on<br />

page<br />

145<br />

v<br />

“Enabling<br />

and<br />

disabling<br />

<strong>for</strong>ms<br />

authentication”<br />

on<br />

page<br />

147<br />

v<br />

“Enable<br />

token<br />

authentication”<br />

on<br />

page<br />

163.<br />

v<br />

“Enable<br />

certificate<br />

authentication”<br />

on<br />

page<br />

151<br />

Note:<br />

Basic<br />

authentication<br />

is<br />

enabled<br />

by<br />

default.<br />

Specify<br />

the<br />

authentication<br />

strength<br />

login<br />

<strong>for</strong>m<br />

When<br />

a<br />

client<br />

attempts<br />

to<br />

access<br />

a<br />

protected<br />

resource,<br />

and<br />

is<br />

required<br />

to<br />

reauthenticate<br />

to<br />

a<br />

higher<br />

authentication<br />

strength<br />

level,<br />

<strong>WebSEAL</strong><br />

presents<br />

a<br />

special<br />

HTML<br />

<strong>for</strong>m.<br />

The<br />

client<br />

uses<br />

the<br />

<strong>for</strong>m<br />

to<br />

supply<br />

the<br />

in<strong>for</strong>mation<br />

needed<br />

<strong>for</strong><br />

the<br />

type<br />

of<br />

authentication<br />

required.<br />

<strong>WebSEAL</strong><br />

supplies<br />

a<br />

default<br />

<strong>for</strong>m.<br />

Administrators<br />

can<br />

either<br />

use<br />

the<br />

default<br />

<strong>for</strong>m<br />

or<br />

customize<br />

it<br />

to<br />

fit<br />

the<br />

local<br />

<strong>WebSEAL</strong><br />

deployment.<br />

The<br />

location<br />

of<br />

the<br />

default<br />

<strong>for</strong>m<br />

is<br />

specified<br />

in<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file:<br />

[acnt-mgt]<br />

stepup-login<br />

=<br />

stepuplogin.html<br />

Complete<br />

the<br />

following<br />

steps:<br />

1.<br />

Specify<br />

the<br />

name<br />

of<br />

the<br />

authentication<br />

strength<br />

login<br />

<strong>for</strong>m.<br />

To<br />

use<br />

the<br />

default<br />

location<br />

<strong>for</strong><br />

the<br />

<strong>for</strong>m,<br />

verify<br />

that<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

entry<br />

<strong>for</strong><br />

stepup-login<br />

contains<br />

the<br />

default<br />

value,<br />

stepuplogin.html.<br />

2.<br />

Optionally,<br />

customize<br />

the<br />

contents<br />

of<br />

the<br />

authentication<br />

strength<br />

login<br />

<strong>for</strong>m.<br />

This<br />

file<br />

contains<br />

macros,<br />

in<br />

the<br />

<strong>for</strong>m<br />

of<br />

%TEXT%<br />

sequences,<br />

which<br />

are<br />

replaced<br />

with<br />

the<br />

appropriate<br />

values.<br />

This<br />

substitution<br />

occurs<br />

within<br />

<strong>WebSEAL</strong>’s<br />

template<br />

file<br />

processing<br />

functions<br />

and<br />

allows<br />

the<br />

<strong>for</strong>m<br />

to<br />

be<br />

used<br />

<strong>for</strong><br />

the<br />

supported<br />

authentication<br />

methods<br />

with<br />

correct<br />

<strong>for</strong>matting.<br />

It<br />

also<br />

allows<br />

other<br />

in<strong>for</strong>mation,<br />

such<br />

as<br />

error<br />

message<br />

and<br />

authentication<br />

method<br />

name,<br />

to<br />

be<br />

supplied<br />

in<br />

the<br />

<strong>for</strong>m<br />

<strong>for</strong><br />

the<br />

user.<br />

For<br />

more<br />

in<strong>for</strong>mation<br />

on<br />

using<br />

macros,<br />

see<br />

“Macro<br />

support<br />

<strong>for</strong><br />

account<br />

management<br />

pages”<br />

on<br />

page<br />

89.<br />

The<br />

configuration<br />

of<br />

authentication<br />

strength<br />

levels<br />

is<br />

now<br />

complete.<br />

120<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!