10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

2.<br />

Manually<br />

edit<br />

krb5.conf<br />

to<br />

remove<br />

a<br />

cryptographic<br />

setting<br />

not<br />

supported<br />

by<br />

Active<br />

Directory.<br />

[libdefaults]<br />

default_tkt_enctypes<br />

=<br />

des-cbc-md5<br />

des-cbc-crc<br />

default_tgs_enctypes<br />

=<br />

des-cbc-md5<br />

des-cbc-crc<br />

This<br />

step<br />

removes<br />

des3-cbc-sha1.<br />

Solaris<br />

Manually<br />

edit<br />

krb5.conf<br />

.<br />

Customize<br />

the<br />

following<br />

in<strong>for</strong>mation<br />

<strong>for</strong><br />

your<br />

domain:<br />

v<br />

Realm<br />

For<br />

example:<br />

<strong>IBM</strong>.COM<br />

v<br />

Active<br />

Directory<br />

controller<br />

server<br />

name<br />

For<br />

example,<br />

dc1.<br />

v<br />

Domain<br />

name<br />

For<br />

example,<br />

ibm.com.<br />

v<br />

DNS<br />

name<br />

For<br />

example,<br />

ibm.com.<br />

Using<br />

the<br />

example<br />

values<br />

above,<br />

the<br />

contents<br />

of<br />

the<br />

Kerberos<br />

configuration<br />

file<br />

would<br />

include<br />

the<br />

following<br />

entries:<br />

/etc/krb5/krb5.conf<br />

–<br />

partial<br />

listing<br />

[libdefaults]<br />

default_realm<br />

=<br />

<strong>IBM</strong>.COM<br />

default_tkt_enctypes<br />

=<br />

des-cbc-md5<br />

des-cbc-crc<br />

default_tgs_enctypes<br />

=<br />

des-cbc-md5<br />

des-cbc-crc<br />

[realms]<br />

<strong>IBM</strong>.COM<br />

=<br />

{<br />

kdc<br />

=<br />

dc1.ibm.com:88<br />

admin_server<br />

=<br />

dc1.ibm.com:749<br />

default_domain<br />

=<br />

ibm.com<br />

}<br />

[domain_realm]<br />

dc1.ibm.com<br />

=<br />

<strong>IBM</strong>.COM<br />

.ibm.com<br />

=<br />

<strong>IBM</strong>.COM<br />

The<br />

last<br />

line<br />

in<br />

the<br />

example<br />

file<br />

above<br />

(<br />

.ibm.com<br />

=<br />

<strong>IBM</strong>.COM<br />

)<br />

represents<br />

the<br />

DNS<br />

domain<br />

in<br />

which<br />

the<br />

<strong>WebSEAL</strong><br />

server<br />

operates<br />

and<br />

to<br />

which<br />

user<br />

connect.<br />

Note<br />

the<br />

dot<br />

(.)<br />

in<br />

front<br />

of<br />

the<br />

<strong>IBM</strong><br />

domain<br />

in<br />

the<br />

last<br />

line.<br />

This<br />

acts<br />

as<br />

a<br />

wildcard<br />

<strong>for</strong><br />

all<br />

hosts<br />

in<br />

the<br />

ibm.com<br />

domain.<br />

Step<br />

5:<br />

Verify<br />

authentication<br />

of<br />

Web<br />

server<br />

principal<br />

(UNIX<br />

only)<br />

Use<br />

the<br />

kinit<br />

program<br />

to<br />

verify<br />

that<br />

the<br />

Kerberos<br />

principal<br />

<strong>for</strong><br />

the<br />

<strong>WebSEAL</strong><br />

server<br />

can<br />

authenticate.<br />

Use<br />

the<br />

password.<br />

specified<br />

when<br />

you<br />

ran<br />

ktpass<br />

in<br />

Step<br />

2:<br />

#<br />

/usr/krb5/bin/kinit<br />

diamond@<strong>IBM</strong>.COM<br />

Password<br />

<strong>for</strong><br />

diamond@<strong>IBM</strong>.COM:<br />

server_password<br />

#<br />

klist<br />

You<br />

should<br />

see<br />

some<br />

output<br />

from<br />

klist<br />

showing<br />

the<br />

credentials<br />

<strong>for</strong><br />

diamond@<strong>IBM</strong>.COM<br />

Chapter<br />

9.<br />

Client<br />

single<br />

sign-on<br />

solutions<br />

241

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!