10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

By<br />

default,<br />

only<br />

one<br />

error<br />

message<br />

is<br />

returned<br />

<strong>for</strong><br />

all<br />

login<br />

failures.<br />

To<br />

specify<br />

an<br />

account<br />

expiry<br />

notification<br />

message,<br />

modify<br />

the<br />

following<br />

setting<br />

in<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file:<br />

[acnt-mgt]<br />

account-expiry-notification<br />

=<br />

yes<br />

The<br />

default<br />

value<br />

is<br />

no.<br />

Logout<br />

and<br />

change<br />

password<br />

commands<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

provides<br />

the<br />

following<br />

commands<br />

<strong>for</strong><br />

supporting<br />

clients<br />

who<br />

authenticate<br />

over<br />

HTTP<br />

or<br />

HTTPS.<br />

pkmslogout<br />

Clients<br />

can<br />

use<br />

the<br />

pkmslogout<br />

command<br />

to<br />

log<br />

out<br />

from<br />

the<br />

current<br />

session<br />

when<br />

they<br />

use<br />

an<br />

authentication<br />

method<br />

that<br />

does<br />

not<br />

supply<br />

authentication<br />

data<br />

with<br />

each<br />

request.<br />

For<br />

example,<br />

pkmslogout<br />

does<br />

not<br />

work<br />

<strong>for</strong><br />

clients<br />

using<br />

basic<br />

authentication,<br />

certificates,<br />

or<br />

IP<br />

address<br />

authentication.<br />

In<br />

this<br />

case,<br />

you<br />

must<br />

close<br />

the<br />

browser<br />

to<br />

log<br />

out.<br />

The<br />

pkmslogout<br />

command<br />

is<br />

appropriate<br />

<strong>for</strong><br />

authentication<br />

using<br />

token<br />

passcode,<br />

<strong>for</strong>ms<br />

authentication,<br />

and<br />

certain<br />

implementations<br />

of<br />

HTTP<br />

header<br />

authentication.<br />

Run<br />

the<br />

command<br />

as<br />

follows:<br />

https://www.tivoli.com/pkmslogout<br />

The<br />

browser<br />

displays<br />

a<br />

logout<br />

<strong>for</strong>m<br />

defined<br />

in<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file:<br />

[acnt-mgt]<br />

logout<br />

=<br />

logout.html<br />

You<br />

can<br />

modify<br />

the<br />

logout.html<br />

file<br />

to<br />

suit<br />

your<br />

requirements.<br />

The<br />

pkmslogout<br />

utility<br />

also<br />

supports<br />

multiple<br />

logout<br />

response<br />

pages<br />

when<br />

the<br />

network<br />

architecture<br />

requires<br />

different<br />

exit<br />

screens<br />

<strong>for</strong><br />

users<br />

logging<br />

out<br />

of<br />

distinctly<br />

different<br />

back-end<br />

systems.<br />

The<br />

following<br />

expression<br />

identifies<br />

a<br />

specific<br />

response<br />

file:<br />

https://www.tivoli.com/pkmslogout?filename=<br />

where<br />

custom_logout_file<br />

is<br />

the<br />

filename<br />

of<br />

the<br />

logout<br />

response.<br />

This<br />

file<br />

must<br />

reside<br />

in<br />

the<br />

same<br />

lib/html/C<br />

directory<br />

that<br />

contains<br />

the<br />

default<br />

logout.html<br />

file<br />

and<br />

other<br />

sample<br />

HTML<br />

response<br />

<strong>for</strong>ms.<br />

pkmspasswd<br />

You<br />

can<br />

use<br />

this<br />

command<br />

to<br />

change<br />

your<br />

login<br />

password<br />

when<br />

using<br />

basic<br />

authentication<br />

(BA)<br />

or<br />

<strong>for</strong>ms<br />

authentication.<br />

This<br />

command<br />

is<br />

appropriate<br />

over<br />

HTTP<br />

or<br />

HTTPS.<br />

For<br />

example:<br />

https://www.tivoli.com/pkmspasswd<br />

To<br />

assure<br />

maximum<br />

security<br />

when<br />

BA<br />

is<br />

used<br />

with<br />

<strong>WebSEAL</strong>,<br />

this<br />

command<br />

has<br />

the<br />

following<br />

behavior<br />

<strong>for</strong><br />

a<br />

BA<br />

client:<br />

1.<br />

The<br />

password<br />

is<br />

changed.<br />

2.<br />

The<br />

client<br />

user<br />

is<br />

logged<br />

out<br />

from<br />

the<br />

current<br />

session.<br />

Chapter<br />

6.<br />

Authentication<br />

143

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!