10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Create<br />

a<br />

protected<br />

object<br />

policy<br />

Complete<br />

the<br />

following<br />

steps:<br />

1.<br />

Create<br />

a<br />

POP.<br />

For<br />

example,<br />

use<br />

pdadmin<br />

to<br />

create<br />

a<br />

new<br />

POP<br />

named<br />

test:<br />

pdadmin><br />

pop<br />

create<br />

test<br />

2.<br />

Display<br />

the<br />

contents<br />

of<br />

the<br />

new<br />

POP:<br />

pdadmin><br />

pop<br />

show<br />

test<br />

The<br />

new<br />

POP<br />

contains<br />

new<br />

settings<br />

similar<br />

to<br />

the<br />

following:<br />

pdadmin><br />

pop<br />

show<br />

test<br />

Protected<br />

object<br />

policy:<br />

test<br />

Description:<br />

Warning:<br />

no<br />

Audit<br />

level:<br />

none<br />

Quality<br />

of<br />

protection:<br />

none<br />

Time<br />

of<br />

day<br />

access:<br />

sun,<br />

mon,<br />

tue,<br />

wed,<br />

thu,<br />

fri,<br />

sat:<br />

anytime:local<br />

IP<br />

Endpoint<br />

Authentication<br />

Method<br />

Policy<br />

Any<br />

Other<br />

Network<br />

0<br />

3.<br />

Note<br />

the<br />

default<br />

values<br />

in<br />

the<br />

POP<br />

<strong>for</strong><br />

the<br />

attribute<br />

IP<br />

Endpoint<br />

Authentication<br />

Method<br />

Policy.<br />

...<br />

...<br />

IP<br />

Endpoint<br />

Authentication<br />

Method<br />

Policy<br />

Any<br />

Other<br />

Network<br />

0<br />

...<br />

The<br />

IP<br />

Endpoint<br />

Authentication<br />

Method<br />

Policy<br />

attribute<br />

is<br />

used<br />

to<br />

specify<br />

two<br />

different<br />

attributes:<br />

v<br />

Authentication<br />

strength<br />

level<br />

The<br />

default<br />

value<br />

is<br />

0.<br />

v<br />

Network-based<br />

access<br />

policy<br />

The<br />

default<br />

value<br />

is<br />

Any<br />

Other<br />

Network.<br />

4.<br />

Use<br />

pdadmin<br />

pop<br />

modify<br />

to<br />

modify<br />

the<br />

IP<br />

Endpoint<br />

Authentication<br />

Method<br />

Policy<br />

attribute<br />

to<br />

specify<br />

the<br />

authentication<br />

strength<br />

level<br />

that<br />

you<br />

want<br />

to<br />

apply<br />

to<br />

the<br />

resources<br />

identified<br />

in<br />

“Establish<br />

an<br />

authentication<br />

strength<br />

policy”<br />

on<br />

page<br />

119.<br />

The<br />

syntax<br />

is:<br />

pdadmin><br />

pop<br />

modify<br />

pop-name<br />

set<br />

ipauth<br />

anyothernw<br />

level-index<br />

The<br />

value<br />

level-index<br />

is<br />

an<br />

integer.<br />

The<br />

default<br />

value<br />

is<br />

0.<br />

The<br />

default<br />

value<br />

maps<br />

to<br />

the<br />

authentication<br />

strength<br />

level<br />

unauthenticated.<br />

Specify<br />

the<br />

index<br />

that<br />

corresponds<br />

to<br />

the<br />

necessary<br />

authentication<br />

strength<br />

level.<br />

To<br />

determine<br />

the<br />

correct<br />

level-index,<br />

examine<br />

the<br />

[authentication-level]<br />

stanza<br />

in<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file.<br />

For<br />

example:<br />

[authentication-levels]<br />

level<br />

=<br />

unauthenticated<br />

level<br />

=<br />

password<br />

level<br />

=<br />

certificate<br />

For<br />

the<br />

above<br />

entry,<br />

the<br />

index<br />

values<br />

are<br />

described<br />

in<br />

the<br />

following<br />

table:<br />

Table<br />

20.<br />

Example<br />

integer<br />

values<br />

<strong>for</strong><br />

authentication<br />

strength<br />

levels<br />

Authentication<br />

method<br />

Index<br />

value<br />

unauthenticated<br />

0<br />

Chapter<br />

5.<br />

<strong>WebSEAL</strong><br />

security<br />

policy<br />

121

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!