10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

[acnt-mgt]<br />

login-redirect-page<br />

=<br />

/jct/intro-page.html<br />

4.<br />

Stop<br />

and<br />

restart<br />

the<br />

<strong>WebSEAL</strong><br />

server.<br />

Disabling<br />

automatic<br />

redirection<br />

To<br />

disable<br />

automatic<br />

redirection,<br />

complete<br />

the<br />

following<br />

steps:<br />

1.<br />

Open<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

<strong>for</strong><br />

editing.<br />

2.<br />

Disable<br />

automatic<br />

redirection<br />

<strong>for</strong><br />

each<br />

of<br />

the<br />

applicable<br />

authentication<br />

methods<br />

by<br />

commenting<br />

or<br />

removing<br />

the<br />

entry<br />

<strong>for</strong><br />

each<br />

authentication<br />

method<br />

in<br />

the<br />

[enable-redirects]<br />

stanza:<br />

[enable-redirects]<br />

#redirect<br />

=<br />

<strong>for</strong>ms-auth<br />

#redirect<br />

=<br />

basic-auth<br />

#redirect<br />

=<br />

token-auth<br />

Note<br />

that<br />

the<br />

hash<br />

character<br />

(<br />

#<br />

)<br />

is<br />

added<br />

to<br />

the<br />

start<br />

of<br />

each<br />

line.<br />

The<br />

example<br />

above<br />

disabled<br />

automatic<br />

redirection<br />

<strong>for</strong><br />

<strong>for</strong>ms<br />

authentication,<br />

basic<br />

authentication,<br />

and<br />

token<br />

authentication.<br />

3.<br />

Stop<br />

and<br />

restart<br />

the<br />

<strong>WebSEAL</strong><br />

server.<br />

Limitations<br />

<strong>WebSEAL</strong><br />

does<br />

not<br />

support<br />

automatic<br />

redirection<br />

at<br />

login<br />

under<br />

the<br />

following<br />

conditions:<br />

v<br />

When<br />

a<br />

Windows<br />

client<br />

has<br />

authenticated<br />

using<br />

SPNEGO<br />

protocol<br />

(and<br />

Kerberos<br />

authentication)<br />

as<br />

part<br />

of<br />

Windows<br />

desktop<br />

single<br />

sign-on.<br />

v<br />

During<br />

reauthentication.<br />

v<br />

When<br />

the<br />

browser<br />

is<br />

reopened<br />

while<br />

using<br />

basic<br />

authentication.<br />

Redirection<br />

works<br />

as<br />

expected<br />

the<br />

first<br />

time<br />

a<br />

user<br />

visits<br />

a<br />

page<br />

with<br />

a<br />

browser<br />

and<br />

authenticates<br />

with<br />

a<br />

valid<br />

user<br />

name<br />

and<br />

password.<br />

However,<br />

if<br />

that<br />

instance<br />

of<br />

the<br />

browser<br />

is<br />

closed<br />

and<br />

another<br />

opened,<br />

the<br />

redirected<br />

page<br />

is<br />

not<br />

displayed<br />

after<br />

the<br />

user<br />

is<br />

authenticated.<br />

Chapter<br />

7.<br />

Advanced<br />

<strong>WebSEAL</strong><br />

authentication<br />

213

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!