10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Authentication<br />

configuration<br />

overview<br />

You<br />

can<br />

enable<br />

and<br />

disable<br />

authentication<br />

<strong>for</strong><br />

both<br />

HTTP<br />

and<br />

HTTPS<br />

clients<br />

on<br />

a<br />

per-method<br />

basis.<br />

The<br />

mechanisms<br />

<strong>for</strong><br />

all<br />

authentication<br />

methods<br />

supported<br />

by<br />

<strong>WebSEAL</strong><br />

are<br />

configured<br />

in<br />

the<br />

[authentication-mechanisms]<br />

stanza<br />

of<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file.<br />

Supported<br />

authentication<br />

method<br />

parameters<br />

include:<br />

v<br />

Local<br />

(built-in)<br />

authenticators<br />

Parameters<br />

<strong>for</strong><br />

local<br />

authenticators<br />

specify<br />

the<br />

appropriate<br />

built-in<br />

shared<br />

library<br />

(UNIX)<br />

or<br />

DLL<br />

(Windows)<br />

files.<br />

v<br />

Custom<br />

external<br />

authenticators<br />

<strong>WebSEAL</strong><br />

provides<br />

template<br />

server<br />

code<br />

that<br />

you<br />

can<br />

use<br />

to<br />

build<br />

and<br />

specify<br />

a<br />

custom<br />

authentication<br />

module.<br />

An<br />

external<br />

authentication<br />

module<br />

specifies<br />

the<br />

appropriate<br />

custom<br />

shared<br />

library.<br />

Authentication<br />

module<br />

parameters<br />

The<br />

following<br />

parameters<br />

specify<br />

local<br />

built-in<br />

authenticators:<br />

Table<br />

22.<br />

Authentication<br />

library<br />

types<br />

specified<br />

in<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

Identifier<br />

Description<br />

passwd-ldap<br />

Library<br />

that<br />

implements<br />

basic<br />

authentication<br />

and<br />

<strong>for</strong>ms<br />

authentication<br />

with<br />

an<br />

LDAP<br />

user<br />

registry.<br />

cert-ssl<br />

Library<br />

that<br />

implements<br />

certificate<br />

authentication.<br />

token-cdas<br />

Library<br />

that<br />

implements<br />

token<br />

authentication.<br />

http-request<br />

Library<br />

that<br />

implements<br />

HTTP<br />

header<br />

or<br />

IP<br />

address<br />

authentication.<br />

sso-create<br />

Library<br />

that<br />

implements<br />

<strong>WebSEAL</strong><br />

single<br />

sign-on<br />

token<br />

creation.<br />

sso-consume<br />

Library<br />

that<br />

implements<br />

<strong>WebSEAL</strong><br />

single<br />

sign-on<br />

token<br />

authentication<br />

(consumption).<br />

passwd-cdas<br />

Library<br />

that<br />

implements<br />

an<br />

authentication<br />

module<br />

library<br />

<strong>for</strong><br />

either<br />

basic<br />

authentication<br />

or<br />

<strong>for</strong>ms<br />

authentication.<br />

cred-ext-attrs<br />

Library<br />

that<br />

implements<br />

credential<br />

extended<br />

attributes<br />

authentication.<br />

su-password<br />

Library<br />

that<br />

implements<br />

switch<br />

user<br />

authentication<br />

<strong>for</strong><br />

basic<br />

authentication<br />

or<br />

<strong>for</strong>ms<br />

authentication.<br />

su-token-card<br />

Library<br />

that<br />

implements<br />

switch<br />

user<br />

authentication<br />

<strong>for</strong><br />

token<br />

authentication.<br />

su-certificate<br />

Library<br />

that<br />

implements<br />

switch<br />

user<br />

authentication<br />

<strong>for</strong><br />

X.509<br />

certificate<br />

authentication.<br />

su-http-request<br />

Library<br />

that<br />

implements<br />

switch<br />

user<br />

authentication<br />

<strong>for</strong><br />

HTTP<br />

header<br />

or<br />

IP<br />

address<br />

authentication.<br />

su-cdsso<br />

Library<br />

that<br />

implements<br />

switch<br />

user<br />

authentication<br />

<strong>for</strong><br />

cross-domain<br />

single<br />

sign-on<br />

authentication.<br />

failover-password<br />

Library<br />

that<br />

implements<br />

failover<br />

cookie<br />

authentication<br />

<strong>for</strong><br />

basic<br />

authentication<br />

or<br />

<strong>for</strong>ms<br />

authentication.<br />

failover-token-card<br />

Library<br />

that<br />

implements<br />

failover<br />

cookie<br />

authentication<br />

<strong>for</strong><br />

token<br />

card<br />

authentication.<br />

140<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!