10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Table<br />

20.<br />

Example<br />

integer<br />

values<br />

<strong>for</strong><br />

authentication<br />

strength<br />

levels<br />

(continued)<br />

password<br />

1<br />

certificate<br />

2<br />

For<br />

example,<br />

to<br />

add<br />

the<br />

password<br />

authentication<br />

strength<br />

level<br />

(index<br />

value<br />

1)<br />

to<br />

the<br />

test<br />

POP,<br />

enter:<br />

pdadmin><br />

pop<br />

modify<br />

test<br />

set<br />

ipauth<br />

anyothernw<br />

1<br />

To<br />

verify<br />

the<br />

modification,<br />

display<br />

the<br />

POP:<br />

pdadmin><br />

pop<br />

show<br />

test<br />

Protected<br />

object<br />

policy:<br />

test<br />

Description:<br />

Test<br />

POP<br />

Warning:<br />

no<br />

Audit<br />

level:<br />

none<br />

Quality<br />

of<br />

protection:<br />

none<br />

Time<br />

of<br />

day<br />

access:<br />

sun,<br />

mon,<br />

tue,<br />

wed,<br />

thu,<br />

fri,<br />

sat:<br />

anytime:local<br />

IP<br />

Endpoint<br />

Authentication<br />

Method<br />

Policy<br />

Any<br />

Other<br />

Network<br />

1<br />

Note:<br />

In<br />

the<br />

above<br />

example,<br />

the<br />

only<br />

valid<br />

index<br />

values<br />

are:<br />

0,1,2.<br />

If<br />

any<br />

other<br />

index<br />

value<br />

is<br />

configured,<br />

<strong>WebSEAL</strong><br />

presents<br />

an<br />

error<br />

page<br />

whenever<br />

a<br />

client<br />

requests<br />

any<br />

object<br />

with<br />

that<br />

has<br />

the<br />

POP<br />

attached.<br />

Specify<br />

network-based<br />

access<br />

restrictions<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

supports<br />

an<br />

optional<br />

POP<br />

configuration<br />

setting<br />

that<br />

enables<br />

the<br />

application<br />

of<br />

authentication<br />

strength<br />

levels<br />

to<br />

client<br />

requests<br />

originating<br />

from<br />

specified<br />

network<br />

addresses.<br />

The<br />

network<br />

addresses<br />

can<br />

be<br />

defined<br />

as<br />

either<br />

a<br />

single<br />

IP<br />

address,<br />

or<br />

as<br />

a<br />

range<br />

of<br />

IP<br />

addresses.<br />

Note:<br />

In<br />

most<br />

deployments,<br />

user<br />

access<br />

is<br />

not<br />

restricted<br />

based<br />

on<br />

the<br />

IP<br />

address<br />

within<br />

POPs.<br />

In<br />

most<br />

deployments,<br />

this<br />

configuration<br />

section<br />

can<br />

be<br />

skipped.<br />

The<br />

pdadmin<br />

pop<br />

modify<br />

set<br />

ipauth<br />

command<br />

is<br />

used<br />

to<br />

specify<br />

IP<br />

addresses.<br />

Note<br />

that<br />

this<br />

is<br />

the<br />

same<br />

pdadmin<br />

command<br />

used<br />

to<br />

specify<br />

authentication<br />

levels.<br />

The<br />

default<br />

usage<br />

of<br />

pdadmin<br />

pop<br />

modify<br />

set<br />

ipauth<br />

does<br />

not<br />

impose<br />

any<br />

network-based<br />

access<br />

restrictions.<br />

This<br />

usage<br />

consists<br />

of<br />

specifying<br />

the<br />

command<br />

line<br />

argument<br />

anyothernw<br />

as<br />

the<br />

value<br />

<strong>for</strong><br />

the<br />

IP<br />

Endpoint<br />

Authentication<br />

Method<br />

Policy<br />

attribute.<br />

This<br />

setting<br />

applies<br />

to<br />

all<br />

user<br />

access,<br />

regardless<br />

of<br />

the<br />

IP<br />

address<br />

of<br />

the<br />

requestor,<br />

and<br />

requires<br />

all<br />

users<br />

to<br />

authenticate<br />

at<br />

the<br />

specified<br />

level.<br />

The<br />

syntax<br />

is:<br />

pdadmin><br />

pop<br />

modify<br />

pop-name<br />

set<br />

ipauth<br />

anyothernw<br />

level_index<br />

For<br />

example,<br />

in<br />

“Create<br />

a<br />

protected<br />

object<br />

policy”<br />

on<br />

page<br />

121<br />

above,<br />

the<br />

following<br />

command<br />

created<br />

a<br />

POP<br />

that<br />

required<br />

all<br />

users<br />

to<br />

authenticate<br />

at<br />

authentication<br />

level<br />

1,<br />

and<br />

did<br />

not<br />

impose<br />

any<br />

network-based<br />

access<br />

requirements:<br />

pdadmin><br />

pop<br />

modify<br />

test<br />

set<br />

ipauth<br />

anyothernw<br />

1<br />

The<br />

following<br />

network-based<br />

access<br />

restrictions<br />

can<br />

be<br />

applied:<br />

122<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!