10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Enable<br />

backwards<br />

compatibility<br />

<strong>for</strong><br />

Version<br />

4.1<br />

tokens<br />

For<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

Version<br />

5.1,<br />

the<br />

<strong>for</strong>mat<br />

of<br />

the<br />

encryption<br />

of<br />

the<br />

authentication<br />

token<br />

was<br />

changed.<br />

This<br />

encryption<br />

algorithm<br />

is<br />

not<br />

backward<br />

compatible.<br />

If<br />

you<br />

are<br />

integrating<br />

authentication<br />

tokens<br />

with<br />

Version<br />

4.1<br />

<strong>WebSEAL</strong><br />

servers,<br />

you<br />

must<br />

specify<br />

a<br />

configuration<br />

file<br />

setting<br />

in<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

to<br />

enable<br />

backwards<br />

compatibility.<br />

Backwards<br />

compatibility<br />

with<br />

the<br />

older<br />

encryption<br />

<strong>for</strong>mat<br />

is<br />

not<br />

enabled<br />

by<br />

default:<br />

[server]<br />

pre-510-compatible-tokens<br />

=<br />

no<br />

To<br />

enable<br />

backwards<br />

compatibility,<br />

set<br />

pre-510-compatible-tokens<br />

to<br />

yes:<br />

[server]<br />

pre-510-compatible-tokens<br />

=<br />

yes<br />

Note:<br />

To<br />

enable<br />

backwards<br />

compatibility<br />

with<br />

<strong>WebSEAL</strong><br />

servers<br />

prior<br />

to<br />

Version<br />

4.1,<br />

you<br />

must<br />

set<br />

an<br />

additional<br />

parameter.<br />

See<br />

“Enabling<br />

compatibility<br />

with<br />

tokens<br />

prior<br />

to<br />

Version<br />

4.1”<br />

on<br />

page<br />

252.<br />

Specify<br />

extended<br />

attributes<br />

to<br />

add<br />

to<br />

token<br />

In<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file,<br />

you<br />

can<br />

specify<br />

extended<br />

attributes<br />

from<br />

a<br />

user<br />

credential<br />

to<br />

add<br />

to<br />

the<br />

cross-domain<br />

single<br />

sign-on<br />

token.<br />

Extended<br />

attributes<br />

consist<br />

of<br />

in<strong>for</strong>mation<br />

about<br />

a<br />

user<br />

identity<br />

that<br />

is<br />

added<br />

to<br />

an<br />

extended<br />

attribute<br />

list<br />

when<br />

a<br />

user<br />

credential<br />

is<br />

created.<br />

Extended<br />

attributes<br />

can<br />

be<br />

added<br />

by<br />

a<br />

number<br />

of<br />

authentication<br />

mechanisms,<br />

including<br />

custom<br />

authentication<br />

modules.<br />

The<br />

custom<br />

authentication<br />

modules<br />

can<br />

be<br />

used,<br />

<strong>for</strong><br />

example,<br />

to<br />

obtain<br />

user<br />

in<strong>for</strong>mation<br />

from<br />

a<br />

registry<br />

that<br />

is<br />

external<br />

to<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong>.<br />

You<br />

can<br />

use<br />

this<br />

setting<br />

to<br />

customize<br />

the<br />

contents<br />

of<br />

the<br />

cross-domain<br />

single<br />

sign-on<br />

token.<br />

This<br />

feature<br />

enables<br />

you<br />

to<br />

tailor<br />

the<br />

token<br />

contents<br />

to<br />

match<br />

the<br />

needs<br />

of<br />

the<br />

destination<br />

domain.<br />

When<br />

you<br />

use<br />

this<br />

feature<br />

to<br />

add<br />

an<br />

attribute<br />

to<br />

a<br />

token,<br />

you<br />

must<br />

also<br />

configure<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

<strong>for</strong><br />

the<br />

server<br />

in<br />

the<br />

destination<br />

domain.<br />

For<br />

the<br />

destination<br />

server,<br />

the<br />

stanza<br />

[cdsso-incoming-<br />

attributes]<br />

is<br />

used<br />

to<br />

specify<br />

the<br />

handling<br />

(extract<br />

or<br />

ignore)<br />

of<br />

each<br />

attribute.<br />

You<br />

can<br />

specify<br />

extended<br />

attributes<br />

by<br />

name,<br />

or<br />

you<br />

can<br />

declare<br />

a<br />

pattern<br />

that<br />

matches<br />

multiple<br />

attribute<br />

names.<br />

You<br />

can<br />

use<br />

standard<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

wildcard-matching<br />

characters.<br />

Table<br />

33.<br />

Supported<br />

wildcard<br />

matching<br />

characters<br />

Character<br />

Description<br />

\<br />

The<br />

character<br />

that<br />

follows<br />

the<br />

backslash<br />

is<br />

part<br />

of<br />

a<br />

special<br />

sequence.<br />

Can<br />

be<br />

used<br />

to<br />

escape<br />

the<br />

other<br />

pattern<br />

matching<br />

characters:<br />

(<br />

?<br />

*<br />

[<br />

]<br />

^<br />

).<br />

To<br />

match<br />

the<br />

backslash<br />

character,<br />

use<br />

″\\″..<br />

?<br />

Wildcard<br />

that<br />

matches<br />

a<br />

single<br />

character.<br />

For<br />

example,<br />

the<br />

string<br />

“abcde”<br />

is<br />

matched<br />

by<br />

the<br />

expression<br />

“ab?de”<br />

*<br />

Wildcard<br />

that<br />

matches<br />

zero<br />

or<br />

more<br />

characters.<br />

[]<br />

Defines<br />

a<br />

set<br />

of<br />

characters,<br />

from<br />

which<br />

any<br />

can<br />

match.<br />

For<br />

example,<br />

the<br />

string<br />

“abcde”<br />

is<br />

matched<br />

with<br />

the<br />

regular<br />

expression<br />

“ab[cty]de”.<br />

^<br />

Indicates<br />

a<br />

negation.<br />

For<br />

example,<br />

the<br />

expression<br />

[^ab]<br />

matches<br />

anything<br />

but<br />

the<br />

‘a’<br />

or<br />

‘b’<br />

characters.<br />

Chapter<br />

9.<br />

Client<br />

single<br />

sign-on<br />

solutions<br />

253

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!