10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

v<br />

When<br />

this<br />

value<br />

is<br />

no,<br />

and<br />

the<br />

session<br />

lifetime<br />

timestamp<br />

is<br />

missing<br />

from<br />

the<br />

failover<br />

cookie,<br />

the<br />

receiving<br />

server<br />

will<br />

view<br />

the<br />

cookie<br />

as<br />

valid.<br />

v<br />

When<br />

this<br />

value<br />

is<br />

yes,<br />

and<br />

the<br />

session<br />

lifetime<br />

timestamp<br />

is<br />

missing<br />

from<br />

the<br />

failover<br />

cookie,<br />

the<br />

receiving<br />

server<br />

will<br />

view<br />

the<br />

cookie<br />

as<br />

not<br />

valid.<br />

v<br />

When<br />

this<br />

value<br />

is<br />

either<br />

no<br />

or<br />

yes,<br />

and<br />

the<br />

session<br />

lifetime<br />

timestamp<br />

is<br />

present<br />

in<br />

the<br />

failover<br />

cookie,<br />

the<br />

receiving<br />

server<br />

evaluates<br />

the<br />

timestamp.<br />

If<br />

the<br />

timestamp<br />

is<br />

not<br />

valid,<br />

the<br />

authentication<br />

fails.<br />

If<br />

the<br />

timestamp<br />

is<br />

valid,<br />

the<br />

authentication<br />

process<br />

proceeds.<br />

Note:<br />

The<br />

session<br />

lifetime<br />

timestamp<br />

is<br />

configured<br />

separately<br />

from<br />

the<br />

session<br />

activity<br />

timestamp.<br />

Require<br />

validation<br />

of<br />

an<br />

activity<br />

timestamp<br />

<strong>WebSEAL</strong><br />

servers<br />

can<br />

optionally<br />

be<br />

configured<br />

to<br />

require<br />

that<br />

each<br />

failover<br />

authentication<br />

cookie<br />

contain<br />

a<br />

session<br />

activity<br />

timestamp.<br />

The<br />

session<br />

activity<br />

timestamp<br />

is<br />

not<br />

required<br />

by<br />

default.<br />

The<br />

default<br />

configuration<br />

file<br />

entry<br />

is:<br />

[failover]<br />

failover-require-activity-timestamp-validation<br />

=<br />

no<br />

This<br />

stanza<br />

entry<br />

is<br />

used<br />

primarily<br />

<strong>for</strong><br />

backwards<br />

compatibility.<br />

Attention:<br />

For<br />

backwards<br />

compatibility<br />

with<br />

failover<br />

cookies<br />

created<br />

by<br />

<strong>WebSEAL</strong><br />

servers<br />

prior<br />

to<br />

Version<br />

5.1,<br />

set<br />

this<br />

entry<br />

to<br />

no.<br />

Failover<br />

authentication<br />

cookies<br />

created<br />

by<br />

<strong>WebSEAL</strong><br />

servers<br />

prior<br />

to<br />

Version<br />

5.1<br />

do<br />

not<br />

contain<br />

this<br />

timestamp.<br />

v<br />

When<br />

this<br />

value<br />

is<br />

no,<br />

and<br />

the<br />

session<br />

activity<br />

timestamp<br />

is<br />

missing<br />

from<br />

the<br />

failover<br />

cookie,<br />

the<br />

receiving<br />

server<br />

will<br />

view<br />

the<br />

cookie<br />

as<br />

valid.<br />

v<br />

When<br />

this<br />

value<br />

is<br />

yes,<br />

and<br />

the<br />

session<br />

activity<br />

timestamp<br />

is<br />

missing<br />

from<br />

the<br />

failover<br />

cookie,<br />

the<br />

receiving<br />

server<br />

will<br />

view<br />

the<br />

cookie<br />

as<br />

not<br />

valid.<br />

v<br />

When<br />

this<br />

value<br />

is<br />

either<br />

no<br />

or<br />

yes,<br />

and<br />

the<br />

session<br />

activity<br />

timestamp<br />

is<br />

present<br />

in<br />

the<br />

failover<br />

cookie,<br />

the<br />

receiving<br />

server<br />

evaluates<br />

the<br />

timestamp.<br />

If<br />

the<br />

timestamp<br />

is<br />

not<br />

valid,<br />

the<br />

authentication<br />

fails.<br />

If<br />

the<br />

timestamp<br />

is<br />

valid,<br />

the<br />

authentication<br />

process<br />

proceeds.<br />

Note:<br />

The<br />

session<br />

activity<br />

timestamp<br />

is<br />

configured<br />

separately<br />

from<br />

the<br />

session<br />

lifetime<br />

timestamp.<br />

Enable<br />

backwards<br />

compatibility<br />

<strong>for</strong><br />

encryption<br />

prior<br />

to<br />

Version<br />

4.1<br />

For<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

Version<br />

4.1,<br />

the<br />

level<br />

of<br />

security<br />

<strong>for</strong><br />

the<br />

encryption<br />

of<br />

the<br />

failover<br />

authentication<br />

cookie<br />

was<br />

increased.<br />

This<br />

encryption<br />

algorithm<br />

is<br />

not<br />

backward<br />

compatible.<br />

If<br />

you<br />

are<br />

integrating<br />

failover<br />

authentication<br />

cookies<br />

with<br />

<strong>WebSEAL</strong><br />

servers<br />

using<br />

versions<br />

of<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

prior<br />

to<br />

Version<br />

4.1,<br />

you<br />

must<br />

specify<br />

a<br />

configuration<br />

file<br />

setting<br />

in<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

to<br />

enable<br />

backwards<br />

compatibility.<br />

Backwards<br />

compatibility<br />

with<br />

the<br />

older<br />

encryption<br />

algorithm<br />

is<br />

not<br />

enabled<br />

by<br />

default:<br />

[server]<br />

pre-410-compatible-tokens<br />

=<br />

no<br />

To<br />

enable<br />

backwards<br />

compatibility,<br />

set<br />

pre-410-compatible-tokens<br />

to<br />

yes:<br />

[server]<br />

pre-410-compatible-tokens<br />

=<br />

yes<br />

180<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!