10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Note:<br />

The<br />

location<br />

of<br />

the<br />

kinit<br />

utility<br />

might<br />

vary<br />

depending<br />

on<br />

the<br />

operating<br />

system<br />

plat<strong>for</strong>m.<br />

Step<br />

6:<br />

Verify<br />

<strong>WebSEAL</strong><br />

authentication<br />

using<br />

the<br />

keytab<br />

file<br />

(UNIX<br />

only)<br />

Verify<br />

that<br />

the<br />

<strong>WebSEAL</strong><br />

server<br />

can<br />

authenticate<br />

using<br />

the<br />

keytab<br />

file<br />

created<br />

in<br />

Step<br />

2.<br />

Enter<br />

the<br />

following<br />

kinit<br />

command<br />

as<br />

one<br />

continuous<br />

command<br />

line:<br />

#<br />

kinit<br />

-k<br />

-t<br />

/var/pdweb/keytab-diamond/diamond_HTTP.keytab<br />

HTTP/diamond.subnet2.ibm.com@<strong>IBM</strong>.COM<br />

#<br />

klist<br />

You<br />

should<br />

see<br />

some<br />

output<br />

from<br />

klist<br />

showing<br />

the<br />

credentials<br />

<strong>for</strong><br />

HTTP/diamond.subnet2.ibm.com@<strong>IBM</strong>.COM<br />

Step<br />

7:<br />

Enable<br />

SPNEGO<br />

<strong>for</strong><br />

<strong>WebSEAL</strong><br />

Modify<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

to<br />

enable<br />

SPNEGO.<br />

Complete<br />

the<br />

following<br />

steps:<br />

v<br />

Stop<br />

the<br />

<strong>WebSEAL</strong><br />

server.<br />

v<br />

Enable<br />

SPNEGO<br />

over<br />

SSL:<br />

[spnego]<br />

spnego-auth<br />

=<br />

https<br />

[authentication-mechanisms]<br />

kerberosv5<br />

=<br />

fully_qualified_path<br />

to<br />

the<br />

library<br />

v<br />

Specify<br />

the<br />

location<br />

of<br />

the<br />

Kerberos<br />

authentication<br />

library:<br />

Table<br />

32.<br />

Kerberos<br />

authentication<br />

library<br />

location<br />

Plat<strong>for</strong>m<br />

File<br />

location<br />

Win32<br />

<strong>Tivoli</strong>_<strong>Access</strong>_<strong>Manager</strong>_install_dir\bin\stliauthn.dll<br />

AIX<br />

/opt/PolicyDirector/lib/libstliauthn.a<br />

Solaris<br />

/opt/PolicyDirector/lib/libstliauthn.so<br />

[authentication-mechanisms]<br />

kerberosv5<br />

=<br />

fully_qualified_path<br />

to<br />

the<br />

library<br />

Step<br />

8:<br />

Add<br />

service<br />

name<br />

and<br />

keytab<br />

file<br />

entries<br />

(UNIX<br />

only)<br />

Modify<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

to<br />

add<br />

the<br />

Kerberos<br />

service<br />

name<br />

and<br />

the<br />

location<br />

of<br />

the<br />

keytab<br />

file:<br />

[spnego]<br />

#<br />

UNIX<br />

ONLY<br />

spnego-krb-service-name<br />

=<br />

HTTP@fully_qualified_hostname_of_webseal_server<br />

#<br />

UNIX<br />

ONLY<br />

spnego-krb-keytab-file<br />

=<br />

fully_qualified_keytab_path<br />

For<br />

example:<br />

[spnego]<br />

#<br />

UNIX<br />

ONLY<br />

spnego-krb-service-name<br />

=<br />

HTTP@diamond.subnet1.ibm.com<br />

#<br />

UNIX<br />

ONLY<br />

spnego-krb-keytab-file<br />

=<br />

/var/pdweb/keytab-diamond/diamond_HTTP.keytab<br />

When<br />

configuring<br />

multiple<br />

<strong>WebSEAL</strong><br />

server<br />

instances,<br />

be<br />

sure<br />

to<br />

enter<br />

the<br />

in<strong>for</strong>mation<br />

<strong>for</strong><br />

the<br />

instance.<br />

For<br />

example,<br />

using<br />

the<br />

prior<br />

example<br />

(in<br />

Step<br />

2)<br />

<strong>for</strong><br />

a<br />

server<br />

instance<br />

named<br />

web1,<br />

enter:<br />

242<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!