10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

v<br />

The<br />

junction<br />

point<br />

name<br />

should<br />

be<br />

unique<br />

and<br />

not<br />

match<br />

any<br />

directory<br />

in<br />

the<br />

Web<br />

space<br />

of<br />

the<br />

local<br />

<strong>WebSEAL</strong><br />

server.<br />

For<br />

example,<br />

if<br />

<strong>WebSEAL</strong><br />

has<br />

resources<br />

of<br />

the<br />

<strong>for</strong>m<br />

/path/...,<br />

do<br />

not<br />

create<br />

a<br />

junction<br />

point<br />

with<br />

the<br />

name<br />

/path.<br />

v<br />

The<br />

junction<br />

point<br />

should<br />

not<br />

match<br />

any<br />

directory<br />

in<br />

the<br />

Web<br />

space<br />

of<br />

the<br />

back-end<br />

server<br />

if<br />

HTML<br />

pages<br />

from<br />

that<br />

server<br />

contain<br />

programs<br />

(such<br />

as<br />

Javascript<br />

or<br />

applets)<br />

with<br />

server-relative<br />

URLs<br />

to<br />

that<br />

directory.<br />

For<br />

example,<br />

if<br />

pages<br />

from<br />

the<br />

back-end<br />

server<br />

contain<br />

programs<br />

with<br />

a<br />

URL<br />

of<br />

<strong>for</strong>m<br />

/path/...,<br />

do<br />

not<br />

create<br />

a<br />

junction<br />

point<br />

of<br />

name<br />

/path.<br />

v<br />

Do<br />

not<br />

create<br />

multiple<br />

<strong>WebSEAL</strong><br />

junctions<br />

that<br />

point<br />

to<br />

the<br />

same<br />

back-end<br />

application<br />

server/port.<br />

This<br />

type<br />

of<br />

configuration<br />

can<br />

cause<br />

unpredictable<br />

control<br />

of<br />

access<br />

to<br />

resources<br />

and<br />

there<strong>for</strong>e<br />

is<br />

not<br />

a<br />

recommended<br />

or<br />

supported<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

configuration<br />

strategy.<br />

Each<br />

<strong>WebSEAL</strong><br />

junction<br />

can<br />

be<br />

secured<br />

by<br />

a<br />

unique<br />

set<br />

of<br />

access<br />

controls<br />

(ACLs).<br />

However,<br />

the<br />

ACL<br />

policy<br />

of<br />

each<br />

newly<br />

created<br />

junction<br />

overlays<br />

the<br />

policies<br />

of<br />

previously<br />

created<br />

junctions<br />

attached<br />

to<br />

the<br />

same<br />

back-end<br />

server/port.<br />

Subsequent<br />

junctions<br />

secured<br />

with<br />

more<br />

permissive<br />

ACLs<br />

can<br />

compromise<br />

previous<br />

junctions<br />

secured<br />

with<br />

less<br />

permissive<br />

ACLs.<br />

<strong>WebSEAL</strong><br />

and<br />

the<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

authorization<br />

model<br />

cannot<br />

guarantee<br />

secure<br />

access<br />

control<br />

with<br />

this<br />

type<br />

of<br />

junction<br />

implementation.<br />

v<br />

<strong>WebSEAL</strong><br />

supports<br />

HTTP<br />

1.1<br />

across<br />

junctions.<br />

Note:<br />

You<br />

can<br />

also<br />

use<br />

the<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

Web<br />

Portal<br />

<strong>Manager</strong><br />

graphical<br />

user<br />

interface<br />

to<br />

create<br />

junctions.<br />

For<br />

more<br />

in<strong>for</strong>mation,<br />

see<br />

the<br />

Web<br />

Portal<br />

<strong>Manager</strong><br />

online<br />

help<br />

screens.<br />

Additional<br />

references<br />

<strong>for</strong><br />

<strong>WebSEAL</strong><br />

junctions<br />

See<br />

“Understanding<br />

<strong>WebSEAL</strong><br />

junctions”<br />

on<br />

page<br />

11<br />

<strong>for</strong><br />

a<br />

conceptual<br />

overview<br />

of<br />

<strong>WebSEAL</strong><br />

junctions.<br />

See<br />

Appendix<br />

B,<br />

“<strong>WebSEAL</strong><br />

junction<br />

reference,”<br />

on<br />

page<br />

491<br />

<strong>for</strong><br />

complete<br />

in<strong>for</strong>mation<br />

on<br />

junction<br />

command<br />

options.<br />

Chapter<br />

10.<br />

<strong>WebSEAL</strong><br />

junctions<br />

277

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!