10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

e-community<br />

single<br />

sign-on<br />

E-community<br />

single<br />

sign-on<br />

is<br />

another<br />

implementation<br />

of<br />

cross-domain<br />

authentication<br />

in<br />

an<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

environment.<br />

The<br />

goal<br />

of<br />

cross-domain<br />

authentication<br />

is<br />

to<br />

allow<br />

users<br />

to<br />

access<br />

resources<br />

across<br />

multiple<br />

servers<br />

in<br />

multiple<br />

domains<br />

without<br />

re-authentication.<br />

An<br />

″e-community″<br />

is<br />

a<br />

group<br />

of<br />

distinct<br />

domains<br />

(<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

or<br />

DNS)<br />

that<br />

participate<br />

in<br />

a<br />

<strong>business</strong><br />

relationship.<br />

These<br />

participating<br />

domains<br />

can<br />

be<br />

configured<br />

as<br />

part<br />

of<br />

one<br />

<strong>business</strong><br />

(and<br />

perhaps<br />

using<br />

different<br />

DNS<br />

names<br />

<strong>for</strong><br />

geographic<br />

reasons)<br />

or<br />

as<br />

disparate<br />

<strong>business</strong>es<br />

with<br />

a<br />

shared<br />

relationship<br />

(<strong>for</strong><br />

example,<br />

company<br />

headquarters,<br />

a<br />

life<br />

insurance<br />

company,<br />

and<br />

a<br />

financial<br />

management<br />

company).<br />

In<br />

either<br />

scenario,<br />

there<br />

is<br />

always<br />

one<br />

domain<br />

that<br />

is<br />

designated<br />

the<br />

″home″<br />

or<br />

″owner″<br />

domain.<br />

In<br />

the<br />

case<br />

of<br />

participating<br />

<strong>business</strong>es,<br />

the<br />

home<br />

domain<br />

owns<br />

the<br />

<strong>business</strong><br />

agreements<br />

that<br />

govern<br />

the<br />

e-community.<br />

In<br />

both<br />

scenarios,<br />

authentication<br />

in<strong>for</strong>mation<br />

about<br />

the<br />

users<br />

who<br />

participate<br />

in<br />

the<br />

e-community<br />

(including<br />

the<br />

user<br />

names<br />

and<br />

passwords<br />

used<br />

<strong>for</strong><br />

authentication)<br />

is<br />

maintained<br />

in<br />

the<br />

home<br />

domain.<br />

This<br />

arrangement<br />

allows<br />

a<br />

single<br />

point<br />

of<br />

reference<br />

<strong>for</strong><br />

administration<br />

issues,<br />

such<br />

as<br />

help<br />

desk<br />

calls<br />

within<br />

the<br />

e-community<br />

that<br />

all<br />

refer<br />

to<br />

the<br />

home<br />

domain.<br />

Alternatively,<br />

you<br />

can<br />

use<br />

the<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

Web<br />

Portal<br />

<strong>Manager</strong><br />

to<br />

delegate<br />

the<br />

management<br />

of<br />

this<br />

in<strong>for</strong>mation<br />

such<br />

that<br />

participating<br />

domains<br />

have<br />

responsibility<br />

<strong>for</strong><br />

the<br />

administration<br />

of<br />

their<br />

own<br />

users.<br />

The<br />

diagram<br />

below<br />

illustrates<br />

a<br />

sample<br />

e-community<br />

with<br />

two<br />

participating<br />

domains:<br />

domain<br />

A<br />

(dA.com)<br />

and<br />

domain<br />

B<br />

(dB.com).<br />

In<br />

this<br />

example,<br />

domain<br />

A<br />

represents<br />

the<br />

home<br />

or<br />

owner<br />

domain.<br />

Domain<br />

B<br />

is<br />

a<br />

participating,<br />

or<br />

″remote″,<br />

domain.<br />

256<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!