10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The<br />

authentication<br />

method<br />

parameters<br />

specify<br />

which<br />

authentication<br />

mechanism<br />

<strong>WebSEAL</strong><br />

uses<br />

to<br />

build<br />

the<br />

user<br />

credential.<br />

Each<br />

of<br />

these<br />

entries<br />

is<br />

required.<br />

<strong>WebSEAL</strong><br />

verifies<br />

that<br />

all<br />

required<br />

data<br />

is<br />

present<br />

in<br />

the<br />

submitted<br />

<strong>for</strong>m.<br />

If<br />

data<br />

is<br />

missing,<br />

the<br />

<strong>for</strong>m<br />

is<br />

returned<br />

to<br />

the<br />

administrator<br />

with<br />

a<br />

descriptive<br />

message.<br />

When<br />

all<br />

required<br />

data<br />

is<br />

present,<br />

<strong>WebSEAL</strong><br />

submits<br />

data<br />

from<br />

the<br />

switch<br />

user<br />

<strong>for</strong>m<br />

data<br />

to<br />

the<br />

/pkmssu.<strong>for</strong>m<br />

action<br />

URL.<br />

Note:<br />

Only<br />

members<br />

of<br />

the<br />

su-admins<br />

group<br />

can<br />

invoke<br />

the<br />

<strong>for</strong>m.<br />

An<br />

ACL<br />

is<br />

not<br />

required<br />

on<br />

this<br />

file.<br />

<strong>WebSEAL</strong><br />

per<strong>for</strong>ms<br />

an<br />

internally<br />

hard-coded<br />

group<br />

membership<br />

check.<br />

<strong>WebSEAL</strong><br />

returns<br />

a<br />

404<br />

″Not<br />

Found″<br />

error<br />

when<br />

the<br />

group<br />

membership<br />

check<br />

fails.<br />

The<br />

full<br />

path<br />

name<br />

<strong>for</strong><br />

the<br />

switch<br />

user<br />

<strong>for</strong>m<br />

is<br />

defined<br />

in<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file.<br />

This<br />

path<br />

name<br />

can<br />

be<br />

modified.<br />

The<br />

values<br />

<strong>for</strong><br />

three<br />

parameters<br />

are<br />

combined<br />

to<br />

build<br />

the<br />

full<br />

path<br />

name:<br />

v<br />

The<br />

server-root<br />

parameter<br />

located<br />

in<br />

the<br />

[server]<br />

stanza<br />

specifies<br />

the<br />

root<br />

of<br />

the<br />

server<br />

hierarchy.<br />

v<br />

The<br />

mgt-pages-root<br />

parameter<br />

in<br />

the<br />

[acnt-mgt]<br />

stanza<br />

specifies<br />

the<br />

localization<br />

sub-directory.<br />

v<br />

The<br />

switch-user<br />

parameter<br />

in<br />

the<br />

[acnt-mgt]<br />

stanza<br />

specifies<br />

the<br />

name<br />

of<br />

the<br />

switch<br />

user<br />

file.<br />

For<br />

example,<br />

on<br />

a<br />

UNIX<br />

system,<br />

the<br />

configuration<br />

file<br />

entries<br />

would<br />

be:<br />

[server]<br />

server-root<br />

=<br />

/opt/pdweb/www-instance_name<br />

....<br />

[acnt-mgt]<br />

mgt-pages-root<br />

=<br />

lib/html/<br />

switch-user<br />

=<br />

switchuser.html<br />

The<br />

value<br />

of<br />

the<br />

LANG<br />

directory<br />

is<br />

specific<br />

to<br />

the<br />

locale.<br />

You<br />

can<br />

determine<br />

the<br />

full<br />

path<br />

to<br />

the<br />

switch<br />

user<br />

<strong>for</strong>m<br />

by<br />

combining<br />

the<br />

values.<br />

For<br />

example,<br />

on<br />

a<br />

UNIX<br />

system,<br />

with<br />

a<br />

U.S.<br />

English<br />

locale<br />

where<br />

the<br />

LANG<br />

directory<br />

is<br />

called<br />

″C″,<br />

the<br />

full<br />

path<br />

would<br />

be:<br />

/opt/pdweb/www-instance_name/lib/html/C/switchuser.html<br />

The<br />

default<br />

value<br />

of<br />

server-root<br />

on<br />

Windows<br />

is:<br />

C:\Program<br />

Files\<strong>Tivoli</strong>\PDWeb\www-instance_name<br />

The<br />

full<br />

path<br />

on<br />

Windows<br />

would<br />

be:<br />

C:\Program<br />

Files\<strong>Tivoli</strong>\PDWeb\www-instance_name\lib\html\C\switchuser.html<br />

How<br />

to<br />

customize<br />

the<br />

HTML<br />

<strong>for</strong>m<br />

To<br />

customize<br />

the<br />

switch<br />

user<br />

<strong>for</strong>m,<br />

open<br />

the<br />

<strong>for</strong>m<br />

<strong>for</strong><br />

editing,<br />

and<br />

complete<br />

the<br />

following<br />

steps:<br />

1.<br />

Specify<br />

the<br />

location<br />

and<br />

contents<br />

of<br />

the<br />

destination<br />

URL.<br />

You<br />

can<br />

configure<br />

this<br />

as<br />

hidden<br />

input<br />

containing<br />

an<br />

appropriate<br />

home<br />

page<br />

or<br />

a<br />

successful<br />

switch<br />

user<br />

confirmation<br />

page.<br />

2.<br />

Specify<br />

the<br />

authentication<br />

methods<br />

You<br />

can<br />

configure<br />

this<br />

field<br />

as<br />

hidden<br />

input.<br />

Valid<br />

values<br />

<strong>for</strong><br />

the<br />

authentication<br />

method<br />

include:<br />

194<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!