10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>WebSEAL</strong>:<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>WebSEAL</strong><br />

is<br />

the<br />

resource<br />

manager<br />

responsible<br />

<strong>for</strong><br />

managing<br />

and<br />

protecting<br />

Web-based<br />

in<strong>for</strong>mation<br />

and<br />

resources.<br />

<strong>WebSEAL</strong><br />

is<br />

a<br />

high<br />

per<strong>for</strong>mance,<br />

multi-threaded<br />

Web<br />

server<br />

that<br />

applies<br />

fine-grained<br />

security<br />

policy<br />

to<br />

the<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

protected<br />

Web<br />

object<br />

space.<br />

<strong>WebSEAL</strong><br />

can<br />

provide<br />

single<br />

sign-on<br />

solutions<br />

and<br />

incorporate<br />

back-end<br />

Web<br />

application<br />

server<br />

resources<br />

into<br />

its<br />

security<br />

policy.<br />

<strong>WebSEAL</strong><br />

normally<br />

acts<br />

as<br />

a<br />

reverse<br />

Web<br />

proxy<br />

by<br />

receiving<br />

HTTP/HTTPS<br />

requests<br />

from<br />

a<br />

Web<br />

browser<br />

and<br />

delivering<br />

content<br />

from<br />

its<br />

own<br />

Web<br />

server<br />

or<br />

from<br />

junctioned<br />

back-end<br />

Web<br />

application<br />

servers.<br />

Requests<br />

passing<br />

through<br />

<strong>WebSEAL</strong><br />

are<br />

evaluated<br />

by<br />

the<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

authorization<br />

service<br />

to<br />

determine<br />

whether<br />

the<br />

user<br />

is<br />

authorized<br />

to<br />

access<br />

the<br />

requested<br />

resource.<br />

<strong>WebSEAL</strong><br />

provides<br />

the<br />

following<br />

features:<br />

v<br />

Supports<br />

multiple<br />

authentication<br />

methods<br />

Both<br />

built-in<br />

and<br />

plug-in<br />

architectures<br />

allow<br />

flexibility<br />

in<br />

supporting<br />

a<br />

variety<br />

of<br />

authentication<br />

mechanisms.<br />

v<br />

Accepts<br />

HTTP<br />

and<br />

HTTPS<br />

requests<br />

v<br />

Integrates<br />

and<br />

protects<br />

back-end<br />

server<br />

resources<br />

through<br />

<strong>WebSEAL</strong><br />

junction<br />

technology<br />

v<br />

Manages<br />

fine-grained<br />

access<br />

control<br />

<strong>for</strong><br />

the<br />

local<br />

and<br />

back-end<br />

server<br />

Web<br />

space<br />

Supported<br />

resources<br />

include<br />

URLs,<br />

URL-based<br />

regular<br />

expressions,<br />

CGI<br />

programs,<br />

HTML<br />

files,<br />

Java<br />

servlets,<br />

and<br />

Java<br />

class<br />

files.<br />

v<br />

Per<strong>for</strong>ms<br />

as<br />

a<br />

reverse<br />

Web<br />

proxy<br />

<strong>WebSEAL</strong><br />

appears<br />

as<br />

a<br />

Web<br />

server<br />

to<br />

clients<br />

and<br />

appears<br />

as<br />

a<br />

Web<br />

browser<br />

to<br />

the<br />

junctioned<br />

back-end<br />

servers<br />

it<br />

is<br />

protecting.<br />

v<br />

Provides<br />

single<br />

sign-on<br />

capabilities<br />

Understanding<br />

the<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

security<br />

model<br />

The<br />

security<br />

policy<br />

<strong>for</strong><br />

a<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

secure<br />

domain<br />

is<br />

maintained<br />

and<br />

governed<br />

by<br />

two<br />

key<br />

security<br />

structures:<br />

v<br />

User<br />

registry<br />

The<br />

user<br />

registry<br />

(such<br />

as<br />

LDAP,<br />

Lotus<br />

Domino,<br />

or<br />

Microsoft<br />

Active<br />

Directory)<br />

contains<br />

all<br />

users<br />

and<br />

groups<br />

who<br />

are<br />

allowed<br />

to<br />

participate<br />

in<br />

the<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

secure<br />

domain.<br />

v<br />

Master<br />

authorization<br />

(policy)<br />

database<br />

The<br />

authorization<br />

database<br />

contains<br />

a<br />

representation<br />

of<br />

all<br />

resources<br />

in<br />

the<br />

domain<br />

(the<br />

protected<br />

object<br />

space).<br />

The<br />

security<br />

administrator<br />

can<br />

dictate<br />

any<br />

level<br />

of<br />

security<br />

by<br />

applying<br />

rules,<br />

known<br />

as<br />

access<br />

control<br />

list<br />

(ACL)<br />

policies<br />

and<br />

protected<br />

object<br />

policies<br />

(POP),<br />

to<br />

those<br />

resources<br />

requiring<br />

protection<br />

The<br />

process<br />

of<br />

authentication<br />

proves<br />

the<br />

identity<br />

of<br />

a<br />

user<br />

to<br />

<strong>WebSEAL</strong>.<br />

A<br />

user<br />

can<br />

participate<br />

in<br />

the<br />

secure<br />

domain<br />

as<br />

authenticated<br />

or<br />

unauthenticated.<br />

Only<br />

users<br />

with<br />

an<br />

entry<br />

in<br />

the<br />

user<br />

registry<br />

can<br />

become<br />

authenticated<br />

users.<br />

Using<br />

ACLs<br />

and<br />

POPs,<br />

the<br />

security<br />

administrator<br />

can<br />

make<br />

certain<br />

public<br />

resources<br />

available<br />

to<br />

unauthenticated<br />

users.<br />

Other<br />

resources<br />

can<br />

be<br />

made<br />

available<br />

only<br />

to<br />

certain<br />

authenticated<br />

users.<br />

2<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!