10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

is-master-authn-server<br />

Use<br />

the<br />

is-master-authn-server<br />

parameter<br />

to<br />

specify<br />

whether<br />

a<br />

server<br />

is<br />

the<br />

MAS<br />

or<br />

not.<br />

Values<br />

include<br />

″yes″<br />

or<br />

″no″.<br />

For<br />

example:<br />

[e-community-sso]<br />

is-master-authn-server<br />

=<br />

yes<br />

Multiple<br />

<strong>WebSEAL</strong>s<br />

can<br />

be<br />

configured<br />

to<br />

act<br />

as<br />

master<br />

authentication<br />

servers<br />

and<br />

then<br />

placed<br />

behind<br />

a<br />

load<br />

balancer.<br />

In<br />

this<br />

scenario,<br />

the<br />

load<br />

balancer<br />

is<br />

″recognized″<br />

as<br />

the<br />

MAS<br />

by<br />

all<br />

other<br />

<strong>WebSEAL</strong><br />

servers<br />

in<br />

the<br />

e-community.<br />

If<br />

the<br />

server<br />

you<br />

are<br />

configuring<br />

is<br />

not<br />

the<br />

MAS,<br />

use<br />

the<br />

master-authn-server<br />

to<br />

specify<br />

to<br />

this<br />

server<br />

the<br />

location<br />

of<br />

the<br />

MAS.<br />

master-authn-server<br />

If<br />

the<br />

is-master-authn-server<br />

parameter<br />

is<br />

set<br />

to<br />

″no″,<br />

this<br />

parameter<br />

must<br />

be<br />

uncommented<br />

and<br />

specified.<br />

The<br />

parameter<br />

identifies<br />

the<br />

fully<br />

qualified<br />

domain<br />

name<br />

of<br />

the<br />

MAS.<br />

For<br />

example:<br />

[e-community-sso]<br />

master-authn-server<br />

=<br />

mas.dA.com<br />

Additionally,<br />

you<br />

can<br />

specify<br />

the<br />

HTTP<br />

and<br />

HTTPS<br />

listening<br />

ports<br />

used<br />

by<br />

the<br />

MAS<br />

if<br />

these<br />

port<br />

values<br />

are<br />

other<br />

than<br />

the<br />

default<br />

(port<br />

80<br />

<strong>for</strong><br />

HTTP<br />

and<br />

port<br />

4443<br />

<strong>for</strong><br />

HTTPS).<br />

master-http-port<br />

If<br />

e-community-sso-auth<br />

enables<br />

HTTP<br />

e-community<br />

authentication<br />

and<br />

the<br />

master<br />

authentication<br />

server<br />

listens<br />

<strong>for</strong><br />

HTTP<br />

requests<br />

on<br />

a<br />

port<br />

other<br />

than<br />

the<br />

standard<br />

HTTP<br />

port<br />

(port<br />

80),<br />

the<br />

master-http-port<br />

parameter<br />

identifies<br />

the<br />

non-standard<br />

port.<br />

This<br />

parameter<br />

is<br />

ignored<br />

if<br />

this<br />

server<br />

is<br />

the<br />

master<br />

authentication<br />

server.<br />

By<br />

default,<br />

this<br />

parameter<br />

is<br />

disabled.<br />

[e-community-sso]<br />

master-http-port<br />

=<br />

<br />

master-https-port<br />

If<br />

e-community-sso-auth<br />

enables<br />

HTTPS<br />

e-community<br />

authentication<br />

and<br />

the<br />

master<br />

authentication<br />

server<br />

listens<br />

<strong>for</strong><br />

HTTPS<br />

requests<br />

on<br />

a<br />

port<br />

other<br />

than<br />

the<br />

standard<br />

HTTPS<br />

port<br />

(port<br />

443),<br />

the<br />

master-http-port<br />

parameter<br />

identifies<br />

the<br />

non-standard<br />

port.<br />

This<br />

parameter<br />

is<br />

ignored<br />

if<br />

this<br />

server<br />

is<br />

the<br />

master<br />

authentication<br />

server.<br />

By<br />

default,<br />

this<br />

parameter<br />

is<br />

disabled.<br />

[e-community-sso]<br />

master-https-port<br />

=<br />

<br />

7.<br />

Specifying<br />

the<br />

″vouch<br />

<strong>for</strong>″<br />

URL<br />

vf-url<br />

The<br />

vf-url<br />

parameter<br />

specifies<br />

the<br />

″vouch<br />

<strong>for</strong>″<br />

URL.<br />

The<br />

value<br />

must<br />

begin<br />

with<br />

a<br />

<strong>for</strong>ward-slash<br />

(/).<br />

The<br />

default<br />

value<br />

is<br />

/pkmsvouch<strong>for</strong>.<br />

Chapter<br />

9.<br />

Client<br />

single<br />

sign-on<br />

solutions<br />

269

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!