10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

4.<br />

Restart<br />

the<br />

<strong>WebSEAL</strong><br />

server.<br />

See<br />

also:<br />

v<br />

“Token<br />

authentication<br />

concepts”<br />

on<br />

page<br />

160<br />

v<br />

“Authentication<br />

libraries”<br />

on<br />

page<br />

419<br />

Enable<br />

access<br />

to<br />

the<br />

SecurID<br />

client<br />

library<br />

For<br />

successful<br />

communication<br />

between<br />

the<br />

SecurID<br />

client<br />

and<br />

ACE/Server,<br />

you<br />

must<br />

manually<br />

set<br />

the<br />

proper<br />

permissions<br />

on<br />

a<br />

SecurID<br />

node<br />

secret<br />

file.<br />

You<br />

must<br />

also<br />

set<br />

an<br />

environment<br />

variable<br />

that<br />

points<br />

<strong>WebSEAL</strong><br />

to<br />

the<br />

location<br />

of<br />

the<br />

node<br />

secret<br />

file.<br />

The<br />

file<br />

is<br />

called<br />

securid.<br />

The<br />

file<br />

is<br />

sent<br />

upon<br />

the<br />

first<br />

successful<br />

authentication<br />

between<br />

the<br />

SecurID<br />

client<br />

and<br />

server.<br />

Subsequent<br />

RSA<br />

client/server<br />

communication<br />

relies<br />

on<br />

an<br />

exchange<br />

of<br />

the<br />

node<br />

secret<br />

to<br />

verify<br />

one<br />

another’s<br />

authenticity.<br />

To<br />

enable<br />

<strong>WebSEAL</strong><br />

to<br />

access<br />

the<br />

SecurID<br />

client<br />

library,<br />

complete<br />

the<br />

following<br />

steps:<br />

1.<br />

Change<br />

the<br />

permissions<br />

of<br />

the<br />

securid<br />

and<br />

sdconf.rec<br />

client<br />

configuration<br />

files<br />

to<br />

allow<br />

read<br />

access<br />

by<br />

the<br />

ivmgr<br />

group.<br />

The<br />

following<br />

example<br />

assumes<br />

that<br />

the<br />

location<br />

of<br />

these<br />

files<br />

is<br />

the<br />

/opt/ace/data<br />

directory:<br />

UNIX:<br />

#<br />

cd<br />

/opt/ace/data<br />

#<br />

chmod<br />

444<br />

securid<br />

#<br />

chmod<br />

444<br />

sdconf.rec<br />

Windows:<br />

Set<br />

the<br />

Security<br />

Properties<br />

on<br />

the<br />

files<br />

to<br />

″Everyone″.<br />

2.<br />

Set<br />

the<br />

VAR_ACE<br />

environment<br />

variable<br />

to<br />

in<strong>for</strong>m<br />

<strong>WebSEAL</strong><br />

of<br />

the<br />

directory<br />

location<br />

of<br />

these<br />

two<br />

files.<br />

The<br />

following<br />

example<br />

assumes<br />

the<br />

location<br />

of<br />

the<br />

files<br />

is<br />

the<br />

/opt/ace/data<br />

directory:<br />

UNIX:<br />

#<br />

export<br />

VAR_ACE=/opt/ace/data<br />

Windows:<br />

Start<br />

><br />

Settings<br />

><br />

Control<br />

Panel<br />

><br />

System<br />

><br />

Environment<br />

For<br />

more<br />

in<strong>for</strong>mation<br />

on<br />

<strong>WebSEAL</strong><br />

support<br />

<strong>for</strong><br />

the<br />

SecurID<br />

client,<br />

see<br />

“Token<br />

authentication<br />

concepts”<br />

on<br />

page<br />

160<br />

Specify<br />

a<br />

customized<br />

password<br />

strength<br />

library<br />

This<br />

configuration<br />

entry<br />

is<br />

required<br />

only<br />

when<br />

a<br />

customized<br />

password<br />

strength<br />

library<br />

is<br />

used.<br />

Edit<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file.<br />

In<br />

the<br />

[authentication-mechanisms]<br />

stanza,<br />

add<br />

an<br />

entry<br />

with<br />

the<br />

entry<br />

keyword<br />

passwd-strength.<br />

Specify<br />

the<br />

name<br />

of<br />

the<br />

customized<br />

password<br />

strength<br />

library<br />

at<br />

the<br />

value<br />

<strong>for</strong><br />

the<br />

entry.<br />

The<br />

following<br />

example<br />

shows<br />

a<br />

sample<br />

configuration<br />

file<br />

entry<br />

<strong>for</strong><br />

use<br />

of<br />

token<br />

authentication<br />

with<br />

a<br />

password<br />

strength<br />

library:<br />

164<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!