10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Disable<br />

certificate<br />

authentication<br />

To<br />

disable<br />

certificate<br />

authentication:<br />

1.<br />

Stop<br />

the<br />

<strong>WebSEAL</strong><br />

server.<br />

2.<br />

Edit<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file.<br />

In<br />

the<br />

[certificate]<br />

stanza,<br />

specify<br />

the<br />

following<br />

key<br />

=<br />

value<br />

pair:<br />

[certificate]<br />

accept-client-certs<br />

=<br />

never<br />

3.<br />

Restart<br />

the<br />

<strong>WebSEAL</strong><br />

server.<br />

Disable<br />

the<br />

Certificate<br />

SSL<br />

ID<br />

cache<br />

The<br />

Certificate<br />

SSL<br />

ID<br />

cache<br />

is<br />

used<br />

only<br />

with<br />

delayed<br />

certificate<br />

authentication<br />

or<br />

authentication<br />

strength<br />

step-up<br />

to<br />

certificate<br />

authentication.<br />

The<br />

disabling<br />

of<br />

the<br />

cache<br />

occurs<br />

automatically,<br />

based<br />

on<br />

the<br />

configuration<br />

settings<br />

<strong>for</strong><br />

certificate<br />

authentication.<br />

To<br />

verify<br />

that<br />

the<br />

cache<br />

is<br />

disabled,<br />

examine<br />

the<br />

value<br />

<strong>for</strong><br />

accept-client-certs<br />

in<br />

the<br />

[certificate]<br />

stanza.<br />

Verify<br />

that<br />

the<br />

value<br />

is<br />

one<br />

of<br />

the<br />

following:<br />

v<br />

required<br />

v<br />

optional<br />

v<br />

never<br />

Verify<br />

that<br />

the<br />

value<br />

is<br />

not<br />

prompt_as_needed.<br />

Chapter<br />

6.<br />

Authentication<br />

155

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!