10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

2.<br />

Edit<br />

/etc/nsswitch.conf<br />

so<br />

the<br />

hosts<br />

line<br />

indicates<br />

the<br />

correct<br />

order<br />

<strong>for</strong><br />

checking<br />

DNS<br />

in<strong>for</strong>mation:<br />

hosts<br />

dns<br />

files<br />

Alternative<br />

goal:<br />

Configure<br />

the<br />

machine<br />

to<br />

first<br />

use<br />

local<br />

DNS<br />

in<strong>for</strong>mation<br />

(/etc/hosts)<br />

be<strong>for</strong>e<br />

checking<br />

DNS.<br />

1.<br />

Configure<br />

the<br />

machine<br />

to<br />

check<br />

/etc/hosts<br />

be<strong>for</strong>e<br />

looking<br />

to<br />

DNS.<br />

Edit<br />

/etc/nsswitch.conf<br />

so<br />

the<br />

hosts<br />

line<br />

indicates<br />

the<br />

correct<br />

order<br />

<strong>for</strong><br />

checking<br />

DNS<br />

in<strong>for</strong>mation:<br />

hosts<br />

files<br />

dns<br />

2.<br />

Enter<br />

appropriate<br />

DNS<br />

in<strong>for</strong>mation<br />

in<br />

/etc/hosts:<br />

webseal1.fully.qualified.com<br />

1.11.111.111<br />

webseal2.fully.qualified.com<br />

2.22.222.222<br />

The<br />

following<br />

general<br />

Windows-specific<br />

in<strong>for</strong>mation<br />

is<br />

provided<br />

only<br />

as<br />

an<br />

example:<br />

1.<br />

Use<br />

DNS<br />

and<br />

specify<br />

2<br />

IP<br />

addresses:<br />

Network<br />

Connections<br />

><br />

LAN<br />

><br />

Properties<br />

><br />

TCP/IP<br />

2.<br />

Specify<br />

a<br />

valid<br />

DNS<br />

server<br />

under<br />

the<br />

Advanced<br />

settings:<br />

Network<br />

Connections<br />

><br />

LAN<br />

><br />

Properties<br />

><br />

TCP/IP<br />

><br />

Advanced<br />

><br />

DNS<br />

><br />

Add...<br />

3.<br />

In<br />

this<br />

same<br />

window,<br />

specify<br />

the<br />

primary<br />

DNS<br />

suffix<br />

<strong>for</strong><br />

this<br />

connection:<br />

Network<br />

Connections<br />

><br />

LAN<br />

><br />

Properties<br />

><br />

TCP/IP<br />

><br />

Advanced<br />

><br />

DNS<br />

><br />

Add...<br />

4.<br />

In<br />

your<br />

system<br />

properties,<br />

specify<br />

the<br />

computer<br />

name<br />

and<br />

its<br />

DNS<br />

suffix:<br />

My<br />

Computer<br />

><br />

Properties<br />

><br />

Network<br />

ID<br />

><br />

Properties<br />

><br />

Computer<br />

name<br />

My<br />

Computer<br />

><br />

Properties<br />

><br />

Network<br />

ID<br />

><br />

Properties<br />

><br />

More<br />

><br />

Primary<br />

DNS<br />

suffix<br />

CDSSO<br />

configuration<br />

summary<br />

The<br />

following<br />

configuration<br />

steps<br />

are<br />

explained<br />

in<br />

detail<br />

in<br />

the<br />

remaining<br />

sections<br />

of<br />

this<br />

CDSSO<br />

chapter<br />

division.<br />

Configuring<br />

default<br />

CDSSO<br />

token<br />

create<br />

functionality<br />

1.<br />

Enable<br />

<strong>WebSEAL</strong><br />

to<br />

generate<br />

CDSSO<br />

tokens<br />

(cdsso-create).<br />

2.<br />

Configure<br />

the<br />

built-in<br />

single<br />

sign-on<br />

authentication<br />

mechanism<br />

(library)<br />

<strong>for</strong><br />

token<br />

create<br />

(sso-create).<br />

3.<br />

Create<br />

the<br />

key<br />

file<br />

used<br />

to<br />

encode<br />

and<br />

decode<br />

the<br />

token.<br />

Copy<br />

the<br />

key<br />

file<br />

to<br />

all<br />

appropriate<br />

participating<br />

servers<br />

([cdsso-peers]<br />

stanza).<br />

4.<br />

Configure<br />

the<br />

token<br />

time<br />

stamp<br />

(authtoken-lifetime)<br />

5.<br />

Configure<br />

the<br />

token<br />

label<br />

parameter<br />

(cdsso-argument).<br />

Configuring<br />

default<br />

CDSSO<br />

token<br />

consume<br />

functionality<br />

1.<br />

Enable<br />

<strong>WebSEAL</strong><br />

to<br />

consume<br />

CDSSO<br />

tokens<br />

(cdsso-auth)<br />

<strong>for</strong><br />

authentication.<br />

2.<br />

Configure<br />

the<br />

built-in<br />

single<br />

sign-on<br />

authentication<br />

mechanism<br />

(library)<br />

<strong>for</strong><br />

token<br />

consume<br />

(sso-consume).<br />

3.<br />

Assign<br />

the<br />

appropriate<br />

key<br />

file<br />

([cdsso-peers]<br />

stanza).<br />

4.<br />

Configure<br />

the<br />

token<br />

time<br />

stamp<br />

(authtoken-lifetime)<br />

5.<br />

Configure<br />

the<br />

token<br />

label<br />

parameter<br />

(cdsso-argument).<br />

248<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!