10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Automatic<br />

redirection<br />

during<br />

user<br />

login<br />

This<br />

section<br />

contains<br />

the<br />

following<br />

topics:<br />

v<br />

“Overview<br />

of<br />

automatic<br />

redirection”<br />

v<br />

“Enabling<br />

automatic<br />

redirection”<br />

v<br />

“Disabling<br />

automatic<br />

redirection”<br />

on<br />

page<br />

213<br />

v<br />

“Limitations”<br />

on<br />

page<br />

213<br />

Overview<br />

of<br />

automatic<br />

redirection<br />

When<br />

a<br />

user<br />

makes<br />

a<br />

request<br />

<strong>for</strong><br />

a<br />

resource<br />

in<br />

a<br />

<strong>WebSEAL</strong><br />

domain,<br />

<strong>WebSEAL</strong><br />

sends<br />

the<br />

resource<br />

to<br />

the<br />

user<br />

upon<br />

successful<br />

authentication<br />

and<br />

policy<br />

checks.<br />

As<br />

an<br />

alternative<br />

to<br />

this<br />

standard<br />

response,<br />

you<br />

can<br />

configure<br />

<strong>WebSEAL</strong><br />

to<br />

automatically<br />

redirect<br />

the<br />

user<br />

to<br />

a<br />

specially<br />

designated<br />

home,<br />

or<br />

welcome<br />

page.<br />

This<br />

<strong>for</strong>ced<br />

redirection<br />

at<br />

login<br />

is<br />

appropriate,<br />

<strong>for</strong><br />

example,<br />

when<br />

users<br />

enter<br />

the<br />

<strong>WebSEAL</strong><br />

domain<br />

through<br />

a<br />

portal<br />

page.<br />

Automatic<br />

redirection<br />

also<br />

overrides<br />

user<br />

attempts<br />

to<br />

directly<br />

access<br />

specific<br />

pages<br />

within<br />

the<br />

domain<br />

by<br />

selecting<br />

user<br />

bookmarks.<br />

The<br />

automatic<br />

redirection<br />

following<br />

process<br />

flow<br />

is<br />

as<br />

follows:<br />

1.<br />

The<br />

user<br />

sends<br />

a<br />

request<br />

and<br />

successfully<br />

authenticates.<br />

2.<br />

<strong>WebSEAL</strong><br />

builds<br />

a<br />

custom<br />

response<br />

and<br />

returns<br />

it<br />

to<br />

the<br />

browser<br />

as<br />

a<br />

redirect.<br />

This<br />

redirect<br />

response<br />

contains<br />

the<br />

URL<br />

value<br />

specified<br />

by<br />

the<br />

login-redirect-page<br />

parameter<br />

in<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file.<br />

3.<br />

The<br />

browser<br />

follows<br />

the<br />

redirect<br />

response<br />

(containing<br />

the<br />

configured<br />

URL).<br />

4.<br />

<strong>WebSEAL</strong><br />

returns<br />

the<br />

page<br />

located<br />

at<br />

the<br />

configured<br />

URL.<br />

Automatic<br />

redirection<br />

at<br />

login<br />

is<br />

enabled<br />

and<br />

disabled<br />

independently<br />

<strong>for</strong><br />

each<br />

authentication<br />

method.<br />

Automatic<br />

redirection<br />

is<br />

supported<br />

<strong>for</strong><br />

the<br />

following<br />

authentication<br />

methods:<br />

v<br />

Basic<br />

authentication<br />

v<br />

Forms<br />

authentication<br />

v<br />

Token<br />

authentication<br />

Enabling<br />

automatic<br />

redirection<br />

To<br />

configure<br />

automatic<br />

redirection,<br />

complete<br />

the<br />

following<br />

steps:<br />

1.<br />

Open<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

<strong>for</strong><br />

editing.<br />

2.<br />

Enable<br />

automatic<br />

redirection<br />

<strong>for</strong><br />

each<br />

of<br />

the<br />

applicable<br />

authentication<br />

methods<br />

by<br />

uncommenting<br />

the<br />

entry<br />

<strong>for</strong><br />

each<br />

method<br />

in<br />

the<br />

[enable-redirects]<br />

stanza:<br />

[enable-redirects]<br />

redirect<br />

=<br />

<strong>for</strong>ms-auth<br />

redirect<br />

=<br />

basic-auth<br />

redirect<br />

=<br />

token-auth<br />

The<br />

example<br />

above<br />

enabled<br />

automatic<br />

redirection<br />

<strong>for</strong><br />

<strong>for</strong>ms<br />

authentication,<br />

basic<br />

authentication,<br />

and<br />

token<br />

authentication.<br />

3.<br />

Specify<br />

the<br />

URL<br />

to<br />

which<br />

the<br />

user<br />

is<br />

redirected<br />

after<br />

login.<br />

The<br />

URL<br />

can<br />

be<br />

expressed<br />

as<br />

an<br />

absolute<br />

or<br />

server-relative<br />

path.<br />

For<br />

example:<br />

[acnt-mgt]<br />

login-redirect-page<br />

=<br />

http://www.ibm.com<br />

or<br />

212<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!