10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>WebSEAL</strong><br />

and<br />

IIS<br />

handle<br />

session<br />

management<br />

differently.<br />

IIS<br />

maintains<br />

session<br />

state<br />

with<br />

clients<br />

by<br />

reauthenticating<br />

each<br />

new<br />

TCP<br />

connection<br />

using<br />

the<br />

SPNEGO<br />

protocol.<br />

SPNEGO<br />

and<br />

Kerberos<br />

are<br />

both<br />

designed<br />

<strong>for</strong><br />

secure<br />

authentication<br />

over<br />

insecure<br />

networks.<br />

In<br />

other<br />

words,<br />

they<br />

are<br />

supposed<br />

to<br />

provide<br />

<strong>for</strong><br />

secure<br />

authentication<br />

even<br />

when<br />

using<br />

an<br />

insecure<br />

transport<br />

such<br />

as<br />

HTTP.<br />

The<br />

IIS<br />

method<br />

of<br />

maintaining<br />

session<br />

state<br />

can<br />

potentially<br />

have<br />

an<br />

adverse<br />

effect<br />

on<br />

per<strong>for</strong>mance.<br />

<strong>WebSEAL</strong><br />

avoids<br />

this<br />

problem<br />

by<br />

using<br />

different<br />

session<br />

state<br />

methods.<br />

The<br />

<strong>WebSEAL</strong><br />

session<br />

state<br />

methods<br />

are<br />

based<br />

on<br />

a<br />

security<br />

model<br />

that<br />

expects<br />

<strong>WebSEAL</strong><br />

to<br />

be<br />

deployed<br />

either<br />

over<br />

a<br />

secure<br />

network<br />

or<br />

using<br />

a<br />

secure<br />

transport<br />

such<br />

as<br />

SSL.<br />

<strong>WebSEAL</strong><br />

optimizes<br />

per<strong>for</strong>mance<br />

by<br />

maintaining<br />

state<br />

using<br />

SSL<br />

session<br />

IDs<br />

or<br />

HTTP<br />

cookies.<br />

Also,<br />

<strong>WebSEAL</strong><br />

provides<br />

a<br />

scalable,<br />

secure<br />

environment<br />

by<br />

supporting<br />

junctions<br />

between<br />

<strong>WebSEAL</strong><br />

and<br />

backend<br />

servers.<br />

Thus,<br />

single<br />

signon<br />

solutions<br />

using<br />

SPNEGO<br />

to<br />

<strong>WebSEAL</strong><br />

should<br />

only<br />

be<br />

deployed<br />

over<br />

a<br />

secure<br />

network<br />

or<br />

over<br />

a<br />

secure<br />

transport<br />

such<br />

as<br />

SSL.<br />

User<br />

registry<br />

and<br />

plat<strong>for</strong>m<br />

support<br />

<strong>WebSEAL</strong><br />

SPNEGO<br />

support<br />

provides<br />

single-sign-on<br />

from<br />

Internet<br />

Explorer<br />

running<br />

on<br />

Windows<br />

workstations<br />

configured<br />

into<br />

Active<br />

Directory<br />

domain<br />

to<br />

<strong>WebSEAL</strong>.<br />

<strong>WebSEAL</strong><br />

provides<br />

SPNEGO<br />

support<br />

<strong>for</strong><br />

use<br />

with<br />

the<br />

following<br />

user<br />

registries:<br />

v<br />

<strong>IBM</strong><br />

Directory<br />

Services<br />

(LDAP)<br />

v<br />

SunOne<br />

LDAP<br />

v<br />

Microsoft<br />

Active<br />

Directory<br />

The<br />

above<br />

user<br />

registries<br />

are<br />

supported<br />

on<br />

the<br />

following<br />

operating<br />

system<br />

releases:<br />

v<br />

<strong>IBM</strong><br />

AIX<br />

5.1<br />

and<br />

5.2<br />

v<br />

Windows<br />

2000<br />

Advanced<br />

Server<br />

v<br />

Windows<br />

2000<br />

Server<br />

v<br />

Sun<br />

Solaris<br />

Operating<br />

Environment<br />

8<br />

and<br />

9<br />

When<br />

Active<br />

Directory<br />

is<br />

not<br />

the<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

user<br />

registry,<br />

users<br />

must<br />

be<br />

replicated<br />

between<br />

the<br />

Active<br />

Directory<br />

registry<br />

and<br />

the<br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

user<br />

registry.<br />

Supported<br />

Windows<br />

client<br />

plat<strong>for</strong>ms:<br />

v<br />

Windows<br />

2000<br />

SP2<br />

(or<br />

greater)<br />

v<br />

Windows<br />

XP<br />

v<br />

Internet<br />

Explorer<br />

5.0.1<br />

or<br />

greater<br />

v<br />

Internet<br />

Explorer<br />

5.5<br />

SP2<br />

v<br />

Internet<br />

Explorer<br />

6.0<br />

SP1<br />

(on<br />

Windows<br />

2000)<br />

Internet<br />

Explorer<br />

must<br />

be<br />

configured<br />

to<br />

participate<br />

in<br />

the<br />

Windows<br />

desktop<br />

single<br />

signon<br />

solution.<br />

Compatibility<br />

with<br />

other<br />

authentication<br />

methods<br />

<strong>WebSEAL</strong><br />

support<br />

<strong>for</strong><br />

SPNEGO<br />

authentication<br />

is<br />

compatible<br />

with<br />

the<br />

following<br />

<strong>WebSEAL</strong><br />

authentication<br />

methods:<br />

v<br />

Basic<br />

authentication<br />

v<br />

Forms<br />

v<br />

HTTP<br />

header<br />

Chapter<br />

9.<br />

Client<br />

single<br />

sign-on<br />

solutions<br />

235

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!