10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

The<br />

attribute_pattern<br />

can<br />

be<br />

either<br />

a<br />

specific<br />

attribute<br />

name,<br />

or<br />

a<br />

case-insensitive<br />

wildcard<br />

expression<br />

that<br />

matches<br />

more<br />

than<br />

one<br />

attribute<br />

name.<br />

For<br />

example,<br />

to<br />

extract<br />

all<br />

attributes<br />

with<br />

the<br />

prefix<br />

tagvalue_,<br />

add<br />

the<br />

following<br />

entry:<br />

[failover-restore-attributes]<br />

tagvalue_*<br />

=<br />

preserve<br />

Attributes<br />

that<br />

do<br />

not<br />

match<br />

any<br />

patterns<br />

specified<br />

with<br />

the<br />

preserve<br />

value<br />

are<br />

not<br />

extracted<br />

from<br />

the<br />

failover<br />

authentication<br />

cookie.<br />

The<br />

order<br />

of<br />

the<br />

stanza<br />

entries<br />

is<br />

important.<br />

Rules<br />

that<br />

appear<br />

earlier<br />

in<br />

[failover-restore-attributes]<br />

take<br />

priority<br />

over<br />

those<br />

placed<br />

later<br />

in<br />

the<br />

stanza.<br />

The<br />

following<br />

attributes<br />

cannot<br />

be<br />

matched<br />

by<br />

a<br />

wildcard<br />

pattern,<br />

but<br />

must<br />

be<br />

explicitly<br />

defined<br />

<strong>for</strong><br />

extraction:<br />

v<br />

Authentication<br />

level<br />

[failover-restore-attributes]<br />

AUTHENTICATION_LEVEL<br />

=<br />

preserve<br />

v<br />

Session<br />

lifetime<br />

timestamp<br />

[failover-restore-attributes]<br />

session-lifetime-timestamp<br />

=<br />

preserve<br />

v<br />

Session<br />

inactivity<br />

timestamp<br />

[failover-restore-attributes]<br />

session-inactivity-timestamp<br />

=<br />

preserve<br />

Enable<br />

domain-wide<br />

failover<br />

cookies<br />

You<br />

can<br />

allow<br />

a<br />

failover<br />

authentication<br />

cookie<br />

to<br />

be<br />

used<br />

by<br />

any<br />

<strong>WebSEAL</strong><br />

server<br />

within<br />

the<br />

same<br />

domain<br />

as<br />

the<br />

<strong>WebSEAL</strong><br />

server<br />

that<br />

creates<br />

the<br />

cookie.<br />

This<br />

feature<br />

is<br />

controlled<br />

by<br />

a<br />

stanza<br />

entry<br />

in<br />

the<br />

[failover]<br />

stanza.<br />

By<br />

default,<br />

domain-wide<br />

failover<br />

cookie<br />

functionality<br />

is<br />

disabled:<br />

[failover]<br />

enable-failover-cookie-<strong>for</strong>-domain<br />

=<br />

no<br />

To<br />

enable<br />

this<br />

feature,<br />

set<br />

enable-failover-cookie-<strong>for</strong>-domain<br />

to<br />

yes:<br />

[failover]<br />

enable-failover-cookie-<strong>for</strong>-domain<br />

=<br />

yes<br />

For<br />

in<strong>for</strong>mation<br />

on<br />

the<br />

effects<br />

of<br />

enabling<br />

this<br />

stanza<br />

entry,<br />

see<br />

“Domain-wide<br />

failover<br />

authentication”<br />

on<br />

page<br />

171.<br />

Require<br />

validation<br />

of<br />

a<br />

lifetime<br />

timestamp<br />

<strong>WebSEAL</strong><br />

servers<br />

can<br />

optionally<br />

be<br />

configured<br />

to<br />

require<br />

that<br />

each<br />

failover<br />

authentication<br />

cookie<br />

contain<br />

a<br />

session<br />

lifetime<br />

timestamp.<br />

The<br />

session<br />

lifetime<br />

timestamp<br />

is<br />

not<br />

required<br />

by<br />

default.<br />

The<br />

default<br />

configuration<br />

file<br />

entry<br />

is:<br />

[failover]<br />

failover-require-lifetime-timestamp-validation<br />

=<br />

no<br />

This<br />

stanza<br />

entry<br />

is<br />

used<br />

primarily<br />

<strong>for</strong><br />

backwards<br />

compatibility.<br />

Attention:<br />

For<br />

backwards<br />

compatibility<br />

with<br />

failover<br />

cookies<br />

created<br />

by<br />

<strong>WebSEAL</strong><br />

servers<br />

prior<br />

to<br />

Version<br />

5.1,<br />

set<br />

this<br />

entry<br />

to<br />

no.<br />

Failover<br />

authentication<br />

cookies<br />

created<br />

by<br />

<strong>WebSEAL</strong><br />

servers<br />

prior<br />

to<br />

Version<br />

5.1<br />

do<br />

not<br />

contain<br />

this<br />

timestamp.<br />

Chapter<br />

6.<br />

Authentication<br />

179

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!