10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

This<br />

chapter<br />

introduces<br />

you<br />

to<br />

important<br />

<strong>WebSEAL</strong><br />

concepts<br />

and<br />

functionality<br />

such<br />

as:<br />

organizing<br />

and<br />

protecting<br />

your<br />

object<br />

space,<br />

authentication,<br />

credentials<br />

acquisition,<br />

and<br />

<strong>WebSEAL</strong><br />

junctions.<br />

v<br />

Chapter<br />

2:<br />

<strong>WebSEAL</strong><br />

server<br />

configuration<br />

This<br />

chapter<br />

is<br />

a<br />

technical<br />

reference<br />

<strong>for</strong><br />

<strong>WebSEAL</strong><br />

configuration<br />

tasks<br />

including:<br />

using<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file,<br />

configuring<br />

communication<br />

parameters,<br />

managing<br />

worker<br />

thread<br />

allocation,<br />

and<br />

configuring<br />

cryptographic<br />

hardware.<br />

v<br />

Chapter<br />

3:<br />

<strong>WebSEAL</strong><br />

server<br />

administration<br />

This<br />

chapter<br />

is<br />

a<br />

technical<br />

reference<br />

<strong>for</strong><br />

<strong>WebSEAL</strong><br />

administration<br />

tasks<br />

including:<br />

managing<br />

the<br />

Web<br />

space<br />

and<br />

using<br />

custom<br />

account<br />

management<br />

pages.<br />

v<br />

Chapter<br />

4:<br />

Serviceability<br />

and<br />

logging<br />

This<br />

chapter<br />

describes<br />

<strong>WebSEAL</strong><br />

support<br />

<strong>for</strong><br />

serviceability,<br />

logging,<br />

and<br />

auditing.<br />

v<br />

Chapter<br />

5:<br />

<strong>WebSEAL</strong><br />

security<br />

policy<br />

This<br />

chapter<br />

provides<br />

detailed<br />

technical<br />

procedures<br />

<strong>for</strong><br />

customizing<br />

security<br />

policy<br />

on<br />

<strong>WebSEAL</strong><br />

including:<br />

ACL<br />

and<br />

POP<br />

policies,<br />

quality<br />

of<br />

protection,<br />

step-up<br />

authentication<br />

policy,<br />

network-based<br />

authentication<br />

policy,<br />

three-strikes<br />

login<br />

policy,<br />

and<br />

password<br />

strength<br />

policy.<br />

v<br />

Chapter<br />

6:<br />

<strong>WebSEAL</strong><br />

authentication<br />

This<br />

chapter<br />

provides<br />

configuration<br />

instructions<br />

<strong>for</strong><br />

setting<br />

up<br />

<strong>WebSEAL</strong><br />

to<br />

manage<br />

a<br />

variety<br />

of<br />

authentication<br />

methods<br />

including:<br />

user<br />

name<br />

and<br />

password,<br />

client-side<br />

certificates,<br />

SecurID<br />

token<br />

passcode,<br />

special<br />

HTTP<br />

header<br />

data,<br />

and<br />

multiplexing<br />

proxy<br />

agents.<br />

v<br />

Chapter<br />

7:<br />

Advanced<br />

<strong>WebSEAL</strong><br />

authentication<br />

This<br />

chapter<br />

provides<br />

detailed<br />

technical<br />

procedures<br />

<strong>for</strong><br />

setting<br />

up<br />

<strong>WebSEAL</strong><br />

<strong>for</strong><br />

advanced<br />

authentication<br />

methods<br />

including:<br />

switch<br />

user<br />

configuration,<br />

server-side<br />

request<br />

caching,<br />

reauthentication,<br />

and<br />

automatic<br />

redirection.<br />

v<br />

Chapter<br />

8:<br />

<strong>WebSEAL</strong><br />

key<br />

management<br />

This<br />

chapter<br />

provides<br />

detailed<br />

technical<br />

procedures<br />

<strong>for</strong><br />

setting<br />

up<br />

<strong>WebSEAL</strong><br />

key<br />

management<br />

including:<br />

server-side<br />

and<br />

client-side<br />

certificate<br />

management,<br />

and<br />

configuring<br />

VeriSign<br />

certificate<br />

status<br />

checking.<br />

v<br />

Chapter<br />

9:<br />

Cross<br />

domain<br />

single<br />

sign-on<br />

solutions<br />

This<br />

chapter<br />

discusses<br />

cross<br />

domain<br />

single<br />

sign-on<br />

solutions<br />

including:<br />

CDSSO<br />

(cross-domain<br />

single<br />

sign-on)<br />

and<br />

e-community.<br />

v<br />

Chapter<br />

10:<br />

<strong>WebSEAL</strong><br />

junctions<br />

This<br />

chapter<br />

is<br />

a<br />

technical<br />

reference<br />

<strong>for</strong><br />

setting<br />

up<br />

and<br />

using<br />

<strong>WebSEAL</strong><br />

junctions.<br />

v<br />

Chapter<br />

11:<br />

Single<br />

sign-on<br />

solutions<br />

across<br />

junctions<br />

This<br />

chapter<br />

discusses<br />

single<br />

sign-on<br />

solutions<br />

<strong>for</strong><br />

the<br />

internal<br />

side<br />

of<br />

a<br />

<strong>WebSEAL</strong><br />

proxy<br />

configuration—between<br />

the<br />

<strong>WebSEAL</strong><br />

server<br />

and<br />

the<br />

back-end<br />

junctioned<br />

application<br />

server.<br />

v<br />

Chapter<br />

12:<br />

Application<br />

integration<br />

This<br />

chapter<br />

discusses<br />

a<br />

variety<br />

of<br />

<strong>WebSEAL</strong><br />

capabilities<br />

<strong>for</strong><br />

integrating<br />

third-party<br />

application<br />

functionality.<br />

v<br />

Chapter<br />

13:<br />

Authorization<br />

decision<br />

in<strong>for</strong>mation<br />

retrieval<br />

This<br />

chapter<br />

discusses<br />

various<br />

mechanisms<br />

<strong>for</strong><br />

obtaining<br />

authorization<br />

decision<br />

in<strong>for</strong>mation<br />

(ADI)<br />

from<br />

<strong>WebSEAL</strong><br />

to<br />

support<br />

the<br />

evaluation<br />

of<br />

authorization<br />

rules<br />

on<br />

protected<br />

resources.<br />

v<br />

Chapter<br />

14:<br />

Attribute<br />

retrieval<br />

service<br />

reference<br />

xviii<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!