10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Forms<br />

authentication<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

provides<br />

<strong>for</strong>ms<br />

authentication<br />

as<br />

an<br />

alternative<br />

to<br />

the<br />

standard<br />

basic<br />

authentication<br />

mechanism.<br />

This<br />

method<br />

produces<br />

a<br />

custom<br />

HTML<br />

login<br />

<strong>for</strong>m<br />

from<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

instead<br />

of<br />

the<br />

standard<br />

login<br />

prompt<br />

resulting<br />

from<br />

a<br />

basic<br />

authentication<br />

challenge.<br />

When<br />

you<br />

use<br />

<strong>for</strong>ms-based<br />

login,<br />

the<br />

browser<br />

does<br />

not<br />

cache<br />

the<br />

username<br />

and<br />

password<br />

in<strong>for</strong>mation<br />

as<br />

it<br />

does<br />

in<br />

basic<br />

authentication.<br />

Enabling<br />

and<br />

disabling<br />

<strong>for</strong>ms<br />

authentication<br />

The<br />

<strong>for</strong>ms-auth<br />

parameter,<br />

located<br />

in<br />

the<br />

[<strong>for</strong>ms]<br />

stanza<br />

of<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file,<br />

enables<br />

and<br />

disables<br />

the<br />

<strong>for</strong>ms<br />

authentication<br />

method.<br />

v<br />

To<br />

enable<br />

the<br />

<strong>for</strong>ms<br />

Authentication<br />

method,<br />

enter<br />

″http″,<br />

″https″,<br />

or<br />

″both″.<br />

v<br />

To<br />

disable<br />

the<br />

<strong>for</strong>ms<br />

Authentication<br />

method,<br />

enter<br />

″none″.<br />

For<br />

example:<br />

[<strong>for</strong>ms]<br />

<strong>for</strong>ms-auth<br />

=<br />

https<br />

Configuring<br />

the<br />

<strong>for</strong>ms<br />

authentication<br />

mechanism<br />

The<br />

passwd-ldap<br />

parameter<br />

specifies<br />

the<br />

shared<br />

library<br />

used<br />

to<br />

process<br />

username<br />

and<br />

password<br />

authentication.<br />

v<br />

On<br />

UNIX,<br />

the<br />

file<br />

that<br />

provides<br />

the<br />

built-in<br />

mapping<br />

function<br />

is<br />

a<br />

shared<br />

library<br />

called<br />

libldapauthn.<br />

v<br />

On<br />

Windows,<br />

the<br />

file<br />

that<br />

provides<br />

the<br />

built-in<br />

mapping<br />

function<br />

is<br />

a<br />

DLL<br />

called<br />

ldapauthn.<br />

Table<br />

24.<br />

Shared<br />

library<br />

names<br />

<strong>for</strong><br />

<strong>for</strong>ms<br />

authentication<br />

Operating<br />

system<br />

Shared<br />

Library<br />

Solaris<br />

libldapauthn.so<br />

AIX<br />

libldapauthn.a<br />

Linux<br />

libldapauthn.so<br />

HP-UX<br />

libldapauthn.sl<br />

Windows<br />

ldapauthn.dll<br />

You<br />

can<br />

configure<br />

the<br />

username<br />

and<br />

password<br />

authentication<br />

mechanism<br />

by<br />

entering<br />

the<br />

passwd-ldap<br />

parameter<br />

with<br />

the<br />

plat<strong>for</strong>m-specific<br />

name<br />

of<br />

the<br />

shared<br />

library<br />

file<br />

in<br />

the<br />

[authentication-mechanism]<br />

stanza<br />

of<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file.<br />

For<br />

example:<br />

Solaris:<br />

[authentication-mechanisms]<br />

passwd-ldap<br />

=<br />

libldapauthn.so<br />

Windows:<br />

[authentication-mechanisms]<br />

passwd-ldap<br />

=<br />

ldapauthn.dll<br />

Chapter<br />

6.<br />

Authentication<br />

147

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!