10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

6.<br />

The<br />

MPA<br />

authenticates<br />

to<br />

<strong>WebSEAL</strong><br />

(using<br />

a<br />

method<br />

distinct<br />

from<br />

the<br />

client)<br />

and<br />

an<br />

identity<br />

is<br />

derived<br />

<strong>for</strong><br />

the<br />

MPA<br />

(which<br />

already<br />

has<br />

a<br />

<strong>WebSEAL</strong><br />

account).<br />

7.<br />

<strong>WebSEAL</strong><br />

verifies<br />

the<br />

MPA’s<br />

membership<br />

in<br />

the<br />

webseal-mpa-servers<br />

group.<br />

8.<br />

A<br />

credential<br />

is<br />

built<br />

<strong>for</strong><br />

the<br />

MPA<br />

and<br />

flagged<br />

as<br />

a<br />

special<br />

MPA<br />

type<br />

in<br />

the<br />

cache.<br />

Although<br />

this<br />

MPA<br />

credential<br />

accompanies<br />

each<br />

future<br />

client<br />

request,<br />

it<br />

is<br />

not<br />

used<br />

<strong>for</strong><br />

authorization<br />

checks<br />

on<br />

these<br />

requests.<br />

9.<br />

Now<br />

<strong>WebSEAL</strong><br />

needs<br />

to<br />

further<br />

identify<br />

the<br />

owner<br />

of<br />

the<br />

request.<br />

The<br />

MPA<br />

is<br />

able<br />

to<br />

distinguish<br />

the<br />

multiple<br />

clients<br />

<strong>for</strong><br />

proper<br />

routing<br />

of<br />

login<br />

prompts.<br />

10.<br />

The<br />

client<br />

logs<br />

in<br />

and<br />

authenticates<br />

using<br />

a<br />

method<br />

distinct<br />

from<br />

the<br />

authentication<br />

type<br />

used<br />

<strong>for</strong><br />

the<br />

MPA.<br />

11.<br />

<strong>WebSEAL</strong><br />

builds<br />

a<br />

credential<br />

from<br />

the<br />

client<br />

authentication<br />

data.<br />

12.<br />

Session<br />

data<br />

type<br />

used<br />

by<br />

each<br />

client<br />

must<br />

be<br />

distinct<br />

from<br />

the<br />

session<br />

data<br />

type<br />

used<br />

by<br />

the<br />

MPA.<br />

13.<br />

The<br />

authorization<br />

service<br />

permits<br />

or<br />

denies<br />

access<br />

to<br />

protected<br />

objects<br />

based<br />

on<br />

the<br />

user<br />

credential<br />

and<br />

the<br />

object’s<br />

ACL<br />

permissions.<br />

Enabling<br />

and<br />

disabling<br />

MPA<br />

authentication<br />

The<br />

mpa<br />

parameter,<br />

located<br />

in<br />

the<br />

[mpa]<br />

stanza<br />

of<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file,<br />

enables<br />

and<br />

disables<br />

MPA<br />

authentication:<br />

v<br />

To<br />

enable<br />

the<br />

MPA<br />

authentication<br />

method,<br />

enter<br />

″yes″.<br />

v<br />

To<br />

disable<br />

the<br />

MPA<br />

authentication<br />

method,<br />

enter<br />

″no″.<br />

For<br />

example:<br />

[mpa]<br />

mpa<br />

=<br />

yes<br />

Create<br />

a<br />

user<br />

account<br />

<strong>for</strong><br />

the<br />

MPA<br />

Refer<br />

to<br />

the<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

Base<br />

Administrator’s<br />

Guide<br />

<strong>for</strong><br />

in<strong>for</strong>mation<br />

on<br />

creating<br />

user<br />

accounts.<br />

Add<br />

the<br />

MPA<br />

account<br />

to<br />

the<br />

webseal-mpa-servers<br />

group<br />

Refer<br />

to<br />

the<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

Base<br />

Administrator’s<br />

Guide<br />

<strong>for</strong><br />

in<strong>for</strong>mation<br />

on<br />

managing<br />

groups.<br />

MPA<br />

authentication<br />

limitations<br />

v<br />

This<br />

release<br />

of<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

supports<br />

only<br />

one<br />

MPA<br />

per<br />

<strong>WebSEAL</strong><br />

server.<br />

v<br />

MPA<br />

authentication<br />

is<br />

not<br />

supported<br />

with<br />

step-up<br />

authentication<br />

configuration.<br />

v<br />

MPA<br />

is<br />

not<br />

supported<br />

with<br />

use-same-session<br />

=<br />

yes<br />

Chapter<br />

6.<br />

Authentication<br />

185

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!