10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

[e-community-domain-keys]<br />

dA.com<br />

=<br />

/abc/xyz/key.fileA-A<br />

dB.com<br />

=/abc/xyz/key.fileA-B<br />

dC.com<br />

=/abc/xyz/key.fileA-C<br />

In<br />

this<br />

example,<br />

key.fileA-A<br />

identifies<br />

the<br />

key<br />

file<br />

used<br />

between<br />

all<br />

of<br />

the<br />

servers<br />

in<br />

domainA.<br />

key.fileA-B<br />

identifies<br />

the<br />

key<br />

file<br />

used<br />

between<br />

domain<br />

A<br />

and<br />

domain<br />

B.<br />

key.fileA-C<br />

identifies<br />

the<br />

key<br />

file<br />

used<br />

between<br />

domain<br />

A<br />

and<br />

domain<br />

C.<br />

Each<br />

remote<br />

server<br />

needs<br />

to<br />

have<br />

a<br />

copy<br />

of<br />

the<br />

appropriate<br />

key<br />

file<br />

used<br />

by<br />

the<br />

MAS.<br />

To<br />

exchange<br />

tokens<br />

with<br />

the<br />

MAS<br />

(domain<br />

A),<br />

all<br />

servers<br />

in<br />

domain<br />

B<br />

require<br />

copies<br />

of<br />

key.fileA-B:<br />

[e-community-domain-keys]<br />

dA.com<br />

=/efg/hij/key.fileA-B<br />

To<br />

exchange<br />

tokens<br />

with<br />

the<br />

MAS<br />

(domain<br />

A),<br />

all<br />

servers<br />

in<br />

domain<br />

C<br />

require<br />

copies<br />

of<br />

key.fileA-C:<br />

[e-community-domain-keys]<br />

dA.com<br />

=/efg/hij/key.fileA-C<br />

Any<br />

servers<br />

in<br />

domain<br />

A<br />

which<br />

use<br />

authentication<br />

services<br />

provided<br />

by<br />

the<br />

MAS<br />

must<br />

have<br />

a<br />

copy<br />

of<br />

key.fileA-A:<br />

[e-community-domain-keys]<br />

dA.com<br />

=/efg/hij/key.fileA-A<br />

In<br />

this<br />

example,<br />

key.fileB-B<br />

identifies<br />

the<br />

key<br />

file<br />

used<br />

between<br />

all<br />

of<br />

the<br />

servers<br />

in<br />

domainB.<br />

Also,<br />

key.fileC-C<br />

identifies<br />

the<br />

key<br />

file<br />

used<br />

between<br />

all<br />

of<br />

the<br />

servers<br />

in<br />

domainC<br />

[e-community-domain-keys]<br />

dB.com<br />

=/efg/hij/key.fileB-B<br />

dC.com<br />

=/efg/hij/key.fileC-C<br />

5.<br />

Configuring<br />

the<br />

″vouch<br />

<strong>for</strong>″<br />

token<br />

label<br />

name<br />

The<br />

authentication<br />

in<strong>for</strong>mation<br />

used<br />

<strong>for</strong><br />

a<br />

single<br />

sign-on<br />

transaction<br />

is<br />

placed<br />

in<br />

the<br />

redirected<br />

request<br />

as<br />

an<br />

encrypted<br />

token<br />

query<br />

string<br />

argument<br />

to<br />

the<br />

request.<br />

This<br />

token<br />

string<br />

requires<br />

a<br />

name,<br />

or<br />

label,<br />

to<br />

identify<br />

it.<br />

The<br />

label<br />

name<br />

uniquely<br />

identifies<br />

the<br />

request<br />

to<br />

the<br />

receiving<br />

<strong>WebSEAL</strong><br />

server<br />

as<br />

a<br />

single<br />

sign-on<br />

request<br />

to<br />

be<br />

handled<br />

by<br />

the<br />

single<br />

sign-on<br />

token<br />

consume<br />

mechanism<br />

(library).<br />

You<br />

must<br />

configure<br />

this<br />

token<br />

label<br />

on<br />

both<br />

<strong>WebSEAL</strong><br />

servers<br />

participating<br />

in<br />

the<br />

single<br />

sign-on<br />

functionality.<br />

To<br />

configure<br />

the<br />

token<br />

label,<br />

use<br />

the<br />

vf-argument<br />

parameter<br />

located<br />

in<br />

the<br />

[e-community-sso]<br />

stanza<br />

of<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file.<br />

For<br />

example<br />

(default):<br />

[e-community-sso]<br />

vf-argument<br />

=<br />

PD-VF<br />

See<br />

“e-community<br />

single<br />

sign-on”<br />

on<br />

page<br />

431.<br />

6.<br />

Specifying<br />

the<br />

master<br />

authentication<br />

server<br />

(MAS)<br />

You<br />

must<br />

specify<br />

which<br />

server<br />

machine<br />

in<br />

the<br />

e-community<br />

is<br />

to<br />

function<br />

as<br />

the<br />

master<br />

authentication<br />

server<br />

(MAS).<br />

You<br />

must<br />

also<br />

specify<br />

if<br />

a<br />

server<br />

machine<br />

is<br />

not<br />

the<br />

MAS.<br />

268<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!