10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

owser<br />

is<br />

Microsoft<br />

Internet<br />

Explorer.<br />

If<br />

this<br />

is<br />

the<br />

case,<br />

configure<br />

the<br />

browser<br />

to<br />

always<br />

check<br />

<strong>for</strong><br />

newer<br />

versions<br />

of<br />

stored<br />

pages:<br />

Tools<br />

><br />

Internet<br />

Options<br />

><br />

General<br />

><br />

Temporary<br />

Internet<br />

Files<br />

><br />

Settings<br />

v<br />

Do<br />

not<br />

configure<br />

the<br />

MAS<br />

server<br />

on<br />

the<br />

same<br />

interface<br />

(IP<br />

address)<br />

of<br />

another<br />

participating<br />

<strong>WebSEAL</strong><br />

server<br />

instance.<br />

v<br />

Because<br />

some<br />

<strong>WebSEAL</strong><br />

configuration<br />

requires<br />

machine<br />

host<br />

names<br />

to<br />

be<br />

described<br />

as<br />

fully<br />

qualified<br />

host<br />

names,<br />

you<br />

must<br />

ensure<br />

that<br />

your<br />

system<br />

and<br />

network<br />

can<br />

resolve<br />

machine<br />

names<br />

into<br />

fully<br />

qualified<br />

host<br />

names.<br />

For<br />

example,<br />

using<br />

fully<br />

qualified<br />

host<br />

names<br />

allows<br />

<strong>for</strong><br />

many<br />

host<br />

names<br />

(IP<br />

addresses)<br />

per<br />

machine,<br />

as<br />

in<br />

the<br />

case<br />

of<br />

multiple<br />

<strong>WebSEAL</strong><br />

instances.<br />

Resolving<br />

machine<br />

names<br />

E-community<br />

can<br />

be<br />

disabled<br />

upon<br />

<strong>WebSEAL</strong><br />

startup<br />

because<br />

the<br />

machine<br />

itself<br />

is<br />

not<br />

adequately<br />

configured<br />

to<br />

resolve<br />

machine<br />

names.<br />

The<br />

machine<br />

on<br />

which<br />

<strong>WebSEAL</strong><br />

resides<br />

needs<br />

to<br />

be<br />

able<br />

to<br />

fully<br />

resolve<br />

an<br />

IP<br />

address.<br />

Because<br />

this<br />

functionality<br />

is<br />

very<br />

operating<br />

system-specific,<br />

it<br />

is<br />

not<br />

the<br />

role<br />

of<br />

this<br />

document<br />

to<br />

provide<br />

instructions.<br />

Always<br />

consult<br />

your<br />

system<br />

administrator<br />

if<br />

you<br />

are<br />

not<br />

sure<br />

your<br />

system<br />

has<br />

the<br />

proper<br />

capabilities.<br />

The<br />

following<br />

general<br />

Solaris-specific<br />

in<strong>for</strong>mation<br />

is<br />

provided<br />

only<br />

as<br />

an<br />

example:<br />

Goal:<br />

Configure<br />

the<br />

machine<br />

to<br />

first<br />

look<br />

to<br />

DNS<br />

be<strong>for</strong>e<br />

checking<br />

the<br />

local<br />

/etc/hosts<br />

file<br />

<strong>for</strong><br />

DNS<br />

in<strong>for</strong>mation.<br />

1.<br />

Make<br />

sure<br />

that<br />

/etc/resolv.conf<br />

has<br />

valid<br />

DNS<br />

server<br />

entries.<br />

2.<br />

Edit<br />

/etc/nsswitch.conf<br />

so<br />

the<br />

hosts<br />

line<br />

indicates<br />

the<br />

correct<br />

order<br />

<strong>for</strong><br />

checking<br />

DNS<br />

in<strong>for</strong>mation:<br />

hosts<br />

dns<br />

files<br />

Alternative<br />

goal:<br />

Configure<br />

the<br />

machine<br />

to<br />

first<br />

use<br />

local<br />

DNS<br />

in<strong>for</strong>mation<br />

(/etc/hosts)<br />

be<strong>for</strong>e<br />

checking<br />

DNS.<br />

1.<br />

Configure<br />

the<br />

machine<br />

to<br />

check<br />

/etc/hosts<br />

be<strong>for</strong>e<br />

looking<br />

to<br />

DNS.<br />

Edit<br />

/etc/nsswitch.conf<br />

so<br />

the<br />

hosts<br />

line<br />

indicates<br />

the<br />

correct<br />

order<br />

<strong>for</strong><br />

checking<br />

DNS<br />

in<strong>for</strong>mation:<br />

hosts<br />

files<br />

dns<br />

2.<br />

Enter<br />

appropriate<br />

DNS<br />

in<strong>for</strong>mation<br />

in<br />

/etc/hosts:<br />

webseal1.fully.qualified.com<br />

1.11.111.111<br />

webseal2.fully.qualified.com<br />

2.22.222.222<br />

The<br />

following<br />

general<br />

Windows-specific<br />

in<strong>for</strong>mation<br />

is<br />

provided<br />

only<br />

as<br />

an<br />

example:<br />

1.<br />

Use<br />

DNS<br />

and<br />

specify<br />

2<br />

IP<br />

addresses:<br />

Network<br />

Connections<br />

><br />

LAN<br />

><br />

Properties<br />

><br />

TCP/IP<br />

2.<br />

Specify<br />

a<br />

valid<br />

DNS<br />

server<br />

under<br />

the<br />

Advanced<br />

settings:<br />

Network<br />

Connections<br />

><br />

LAN<br />

><br />

Properties<br />

><br />

TCP/IP<br />

><br />

Advanced<br />

><br />

DNS<br />

><br />

Add...<br />

3.<br />

In<br />

this<br />

same<br />

window,<br />

specify<br />

the<br />

primary<br />

DNS<br />

suffix<br />

<strong>for</strong><br />

this<br />

connection:<br />

Network<br />

Connections<br />

><br />

LAN<br />

><br />

Properties<br />

><br />

TCP/IP<br />

><br />

Advanced<br />

><br />

DNS<br />

><br />

Add...<br />

4.<br />

In<br />

your<br />

system<br />

properties,<br />

specify<br />

the<br />

computer<br />

name<br />

and<br />

its<br />

DNS<br />

suffix:<br />

My<br />

Computer<br />

><br />

Properties<br />

><br />

Network<br />

ID<br />

><br />

Properties<br />

><br />

Computer<br />

name<br />

My<br />

Computer<br />

><br />

Properties<br />

><br />

Network<br />

ID<br />

><br />

Properties<br />

><br />

More<br />

><br />

Primary<br />

DNS<br />

suffix<br />

E-community<br />

configuration<br />

summary<br />

An<br />

e-community<br />

is<br />

configured<br />

under<br />

the<br />

following<br />

conditions<br />

and<br />

guidelines:<br />

264<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!