10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Thus,<br />

the<br />

default<br />

value<br />

<strong>for</strong><br />

cert-cache-max-entries<br />

is<br />

1024,<br />

which<br />

is<br />

one<br />

quarter<br />

of<br />

the<br />

default<br />

value<br />

<strong>for</strong><br />

ssl-max-entries,<br />

which<br />

is<br />

4096.<br />

Note:<br />

Most<br />

client<br />

requests<br />

to<br />

<strong>WebSEAL</strong><br />

occur<br />

over<br />

SSL<br />

connections,<br />

and<br />

all<br />

requests<br />

over<br />

SSL<br />

connections<br />

without<br />

certificates<br />

must<br />

check<br />

the<br />

cache.<br />

Thus,<br />

keeping<br />

the<br />

cache<br />

size<br />

smaller<br />

can<br />

significantly<br />

improve<br />

per<strong>for</strong>mance.<br />

Set<br />

the<br />

timeout<br />

<strong>for</strong><br />

Certificate<br />

SSL<br />

ID<br />

cache<br />

This<br />

configuration<br />

step<br />

applies<br />

only<br />

when<br />

delayed<br />

certificate<br />

authentication<br />

has<br />

been<br />

enabled.<br />

Complete<br />

the<br />

following<br />

steps:<br />

1.<br />

Verify<br />

that<br />

certificate<br />

authentication<br />

is<br />

enabled.<br />

See<br />

“Enable<br />

certificate<br />

authentication”<br />

on<br />

page<br />

151<br />

2.<br />

Edit<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file.<br />

In<br />

the<br />

[certificate]<br />

stanza,<br />

adjust<br />

the<br />

value<br />

of<br />

cert-cache-timeout<br />

as<br />

necessary.<br />

[certificate]<br />

cert-cache-timeout<br />

=<br />

120<br />

The<br />

value<br />

is<br />

the<br />

maximum<br />

lifetime<br />

<strong>for</strong><br />

an<br />

entry<br />

in<br />

the<br />

cache,<br />

expressed<br />

as<br />

a<br />

number<br />

of<br />

seconds.<br />

Use<br />

the<br />

default<br />

value<br />

unless<br />

your<br />

conditions<br />

warrant<br />

modifying<br />

it.<br />

Possible<br />

reasons<br />

to<br />

modify<br />

the<br />

value:<br />

v<br />

Systems<br />

with<br />

memory<br />

restrictions<br />

may<br />

want<br />

to<br />

reduce<br />

the<br />

expiration<br />

time.<br />

v<br />

The<br />

expiration<br />

time<br />

might<br />

need<br />

to<br />

be<br />

increased<br />

if<br />

there<br />

is<br />

a<br />

significant<br />

lag<br />

between<br />

the<br />

time<br />

when<br />

the<br />

user<br />

initiates<br />

a<br />

certificate<br />

transfer<br />

and<br />

when<br />

the<br />

user<br />

actually<br />

submits<br />

the<br />

certificate.<br />

v<br />

Lower<br />

values<br />

clean<br />

out<br />

the<br />

cache<br />

sooner<br />

when<br />

no<br />

certificate<br />

authentications<br />

are<br />

required.<br />

This<br />

frees<br />

system<br />

memory.<br />

Specify<br />

an<br />

error<br />

page<br />

<strong>for</strong><br />

incorrect<br />

protocol<br />

This<br />

configuration<br />

step<br />

applies<br />

only<br />

when<br />

delayed<br />

certificate<br />

authentication<br />

has<br />

been<br />

enabled.<br />

<strong>WebSEAL</strong><br />

provides<br />

a<br />

default<br />

HTML<br />

page<br />

containing<br />

an<br />

error<br />

message<br />

to<br />

be<br />

displayed<br />

when<br />

an<br />

authenticated<br />

user<br />

attempts<br />

to<br />

increase<br />

the<br />

authentication<br />

strength<br />

level<br />

to<br />

client<br />

authentication<br />

from<br />

an<br />

HTTP<br />

session.<br />

Users<br />

attempting<br />

to<br />

increase<br />

authentication<br />

level<br />

to<br />

certificate<br />

authentication<br />

must<br />

use<br />

the<br />

HTTPS<br />

protocol.<br />

Administrators<br />

can<br />

choose<br />

to<br />

either<br />

use<br />

the<br />

default<br />

error<br />

page,<br />

customize<br />

the<br />

error<br />

message,<br />

or<br />

specify<br />

an<br />

entirely<br />

different<br />

customized<br />

error<br />

page.<br />

Typically,<br />

administrators<br />

use<br />

the<br />

default<br />

page<br />

but<br />

might<br />

customize<br />

the<br />

contents<br />

of<br />

the<br />

error<br />

message.<br />

Administrators<br />

who<br />

choose<br />

to<br />

create<br />

a<br />

new<br />

HTML<br />

error<br />

page<br />

must<br />

edit<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

to<br />

indicate<br />

the<br />

location<br />

of<br />

the<br />

new<br />

page.<br />

The<br />

default<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

entry<br />

is:<br />

[acnt-mgt]<br />

cert-stepup-http<br />

=<br />

certstepuphttp.html<br />

154<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!