10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Setting<br />

Description<br />

accept-client-certs<br />

=<br />

prompt_as_needed<br />

Client<br />

is<br />

not<br />

required<br />

to<br />

authenticate<br />

with<br />

a<br />

certificate<br />

at<br />

session<br />

start-up.<br />

The<br />

client<br />

can<br />

later<br />

initiate<br />

certificate<br />

authentication.<br />

This<br />

setting<br />

enables<br />

delayed<br />

certificate<br />

authentication<br />

mode.<br />

For<br />

example,<br />

to<br />

prompt<br />

users<br />

<strong>for</strong><br />

a<br />

client<br />

certificate<br />

only<br />

when<br />

the<br />

client<br />

encounters<br />

a<br />

resource<br />

that<br />

requires<br />

certificate<br />

authentication,<br />

enter:<br />

[certificate]<br />

accept-client-certs<br />

=<br />

prompt_as_needed<br />

Note<br />

that<br />

this<br />

setting<br />

is<br />

used<br />

when<br />

implementing<br />

an<br />

authentication<br />

strength<br />

policy<br />

(step-up)<br />

<strong>for</strong><br />

certificate<br />

authentication.<br />

2.<br />

When<br />

accept-client-certs<br />

is<br />

set<br />

to<br />

either<br />

optional<br />

or<br />

required,<br />

skip<br />

this<br />

step<br />

and<br />

continue<br />

to<br />

the<br />

next<br />

step.<br />

Specify<br />

the<br />

certificate<br />

authentication<br />

mechanism<br />

To<br />

specify<br />

a<br />

certificate<br />

authentication<br />

mechanism,<br />

complete<br />

the<br />

following<br />

steps:<br />

1.<br />

Verify<br />

that<br />

certificate<br />

authentication<br />

is<br />

enabled.<br />

See<br />

“Enable<br />

certificate<br />

authentication”<br />

on<br />

page<br />

151.<br />

2.<br />

Edit<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file.<br />

In<br />

the<br />

[certificate]<br />

stanza,<br />

specify<br />

the<br />

appropriate<br />

certificate<br />

authentication<br />

built-in<br />

shared<br />

library<br />

as<br />

the<br />

value<br />

<strong>for</strong><br />

the<br />

cert-ssl<br />

key:<br />

Table<br />

25.<br />

Certificate<br />

authentication<br />

shared<br />

libraries<br />

Operating<br />

system<br />

Shared<br />

library<br />

Solaris<br />

libsslauthn.so<br />

AIX<br />

libsslauthn.a<br />

HPUX<br />

libsslauthn.sl<br />

Linux<br />

libsslauthn.so<br />

Windows<br />

sslauthn.dll<br />

For<br />

example,<br />

on<br />

a<br />

Solaris<br />

system:<br />

[authentication-mechanisms]<br />

cert-ssl=<br />

libsslauthn.so<br />

See<br />

also:<br />

v<br />

“Authentication<br />

methods”<br />

on<br />

page<br />

414<br />

v<br />

“Authentication<br />

libraries”<br />

on<br />

page<br />

419<br />

Specify<br />

the<br />

certificate<br />

login<br />

<strong>for</strong>m<br />

<strong>WebSEAL</strong><br />

provides<br />

an<br />

HTML<br />

page<br />

containing<br />

a<br />

login<br />

<strong>for</strong>m,<br />

to<br />

be<br />

presented<br />

to<br />

users<br />

when<br />

the<br />

need<br />

<strong>for</strong><br />

certificate<br />

authentication<br />

has<br />

been<br />

identified.<br />

Administrators<br />

can<br />

choose<br />

to<br />

either<br />

use<br />

the<br />

default<br />

login<br />

<strong>for</strong>m,<br />

customize<br />

the<br />

login<br />

<strong>for</strong>m,<br />

or<br />

specify<br />

an<br />

entirely<br />

different<br />

customized<br />

login<br />

page.<br />

Typically,<br />

administrators<br />

use<br />

the<br />

default<br />

file<br />

but<br />

customize<br />

the<br />

contents<br />

of<br />

the<br />

<strong>for</strong>m.<br />

Administrators<br />

who<br />

choose<br />

to<br />

create<br />

a<br />

new<br />

HTML<br />

file<br />

must<br />

edit<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

to<br />

indicate<br />

the<br />

location<br />

of<br />

the<br />

new<br />

file.<br />

152<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!