10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

highly<br />

secure<br />

password,<br />

such<br />

as<br />

a<br />

randomly<br />

generated<br />

password,<br />

is<br />

preferred.<br />

The<br />

location<br />

of<br />

the<br />

keytab<br />

file<br />

is<br />

arbitrary.<br />

Retain<br />

this<br />

password,<br />

<strong>for</strong><br />

use<br />

in<br />

a<br />

later<br />

step<br />

to<br />

test<br />

your<br />

Kerberos<br />

configuration<br />

(when<br />

testing<br />

authentication<br />

from<br />

a<br />

UNIX<br />

machine<br />

to<br />

the<br />

Active<br />

Directory<br />

Key<br />

Distribution<br />

Center).<br />

2.<br />

Transfer<br />

the<br />

keytab<br />

file<br />

to<br />

the<br />

UNIX<br />

system.<br />

Ensure<br />

that<br />

a<br />

secure<br />

transfer<br />

method<br />

is<br />

used.<br />

The<br />

recommended<br />

location<br />

is:<br />

/var/pdweb/keytab-instance_name/keytab_file_name<br />

3.<br />

For<br />

best<br />

security<br />

practice,<br />

delete<br />

the<br />

keytab<br />

file<br />

from<br />

the<br />

Windows<br />

system.<br />

4.<br />

On<br />

the<br />

UNIX<br />

system,<br />

assign<br />

ownership<br />

of<br />

the<br />

file<br />

to<br />

ivmgr,<br />

and<br />

restrict<br />

permissions<br />

on<br />

the<br />

keytab<br />

file<br />

so<br />

that<br />

only<br />

the<br />

owner<br />

can<br />

access<br />

it.<br />

For<br />

example:<br />

#<br />

chown<br />

ivmgr<br />

keytab_file<br />

#<br />

chgrp<br />

ivmgr<br />

keytab_file<br />

#<br />

chmod<br />

600<br />

keytab_file<br />

5.<br />

For<br />

UNIX<br />

servers,<br />

repeat<br />

the<br />

above<br />

steps<br />

<strong>for</strong><br />

each<br />

<strong>WebSEAL</strong><br />

server<br />

instance.<br />

Step<br />

3:<br />

Install<br />

Kerberos<br />

runtime<br />

client<br />

(UNIX<br />

only)<br />

The<br />

<strong>WebSEAL</strong><br />

server<br />

system<br />

must<br />

have<br />

a<br />

Kerberos<br />

runtime<br />

installed.<br />

On<br />

Windows<br />

systems,<br />

the<br />

Kerberos<br />

runtime<br />

client<br />

is<br />

part<br />

of<br />

the<br />

operating<br />

system.<br />

No<br />

additional<br />

packages<br />

are<br />

required.<br />

On<br />

UNIX<br />

systems,<br />

install<br />

the<br />

appropriate<br />

package:<br />

v<br />

AIX<br />

<strong>IBM</strong><br />

Network<br />

Authentication<br />

Service<br />

Client.<br />

This<br />

client<br />

can<br />

be<br />

found<br />

in<br />

the<br />

AIX<br />

expansion<br />

pack.<br />

v<br />

Solaris<br />

–<br />

<strong>IBM</strong><br />

Network<br />

Authentication<br />

Service<br />

Client.<br />

This<br />

client<br />

is<br />

included<br />

on<br />

the<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

Web<br />

Security<br />

CD.<br />

Use<br />

pkgadd<br />

to<br />

install.<br />

–<br />

SUN<br />

Kerberos<br />

Client<br />

SUNWkr5cl.<br />

This<br />

is<br />

required<br />

by<br />

the<br />

<strong>IBM</strong><br />

Network<br />

Authentication<br />

Service<br />

Client.<br />

This<br />

package<br />

is<br />

part<br />

of<br />

the<br />

SEAM<br />

package,<br />

and<br />

can<br />

be<br />

downloaded<br />

from<br />

the<br />

Sun<br />

Web<br />

site.<br />

Step<br />

4:<br />

Configure<br />

Kerberos<br />

client<br />

(UNIX<br />

only)<br />

The<br />

Kerberos<br />

client<br />

installed<br />

in<br />

the<br />

previous<br />

step<br />

must<br />

be<br />

configured.<br />

This<br />

requires<br />

creation<br />

or<br />

modification<br />

of<br />

a<br />

Kerberos<br />

configuration<br />

file.<br />

On<br />

Solaris<br />

and<br />

AIX<br />

the<br />

file<br />

is:<br />

/etc/krb5/krb5.conf<br />

Complete<br />

the<br />

instructions<br />

that<br />

apply<br />

to<br />

your<br />

operating<br />

system:<br />

AIX<br />

Use<br />

the<br />

mkkrb5clnt<br />

utility.<br />

This<br />

utility<br />

creates<br />

and<br />

completes<br />

/etc/krb5/krb5.conf.<br />

1.<br />

Run<br />

mkkrb5clnt.<br />

The<br />

syntax<br />

is:<br />

mkkrb5clnt<br />

-r<br />

Active_Directory_domain<br />

-c<br />

Active_Directory_controller_DNS<br />

-s<br />

Active_Directory_controller_DNS<br />

-d<br />

local_DNS_domain<br />

For<br />

example:<br />

mkkrb5clnt<br />

-r<br />

<strong>IBM</strong>.COM<br />

-c<br />

dc1.ibm.com<br />

-s<br />

dc1.ibm.com<br />

-d<br />

dns.com<br />

240<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!