10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring<br />

single<br />

sign-on<br />

<strong>for</strong>ms<br />

authentication<br />

Single<br />

sign-on<br />

<strong>for</strong>ms<br />

authentication<br />

allows<br />

<strong>WebSEAL</strong><br />

to<br />

transparently<br />

log<br />

an<br />

authenticated<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

user<br />

in<br />

to<br />

a<br />

back-end<br />

junctioned<br />

application<br />

server<br />

that<br />

requires<br />

authentication<br />

via<br />

an<br />

HTML<br />

<strong>for</strong>m.<br />

Background<br />

and<br />

goals<br />

Single<br />

sign-on<br />

<strong>for</strong>ms<br />

authentication<br />

supports<br />

existing<br />

applications<br />

that<br />

use<br />

HTML<br />

<strong>for</strong>ms<br />

<strong>for</strong><br />

authentication<br />

and<br />

cannot<br />

be<br />

modified<br />

to<br />

directly<br />

trust<br />

the<br />

authentication<br />

per<strong>for</strong>med<br />

by<br />

<strong>WebSEAL</strong>.<br />

Enabling<br />

single<br />

sign-on<br />

<strong>for</strong>ms<br />

authentication<br />

produces<br />

the<br />

following<br />

results:<br />

v<br />

<strong>WebSEAL</strong><br />

interrupts<br />

the<br />

authentication<br />

process<br />

initiated<br />

by<br />

the<br />

back-end<br />

application<br />

v<br />

<strong>WebSEAL</strong><br />

supplies<br />

data<br />

required<br />

by<br />

the<br />

login<br />

<strong>for</strong>m<br />

and<br />

submits<br />

the<br />

login<br />

<strong>for</strong>m<br />

on<br />

behalf<br />

of<br />

the<br />

user.<br />

v<br />

<strong>WebSEAL</strong><br />

saves<br />

and<br />

restores<br />

all<br />

cookies<br />

and<br />

headers<br />

v<br />

The<br />

user<br />

is<br />

unaware<br />

that<br />

a<br />

second<br />

login<br />

is<br />

taking<br />

place.<br />

v<br />

The<br />

back-end<br />

application<br />

is<br />

unaware<br />

that<br />

the<br />

login<br />

<strong>for</strong>m<br />

is<br />

not<br />

coming<br />

directly<br />

from<br />

the<br />

user.<br />

<strong>WebSEAL</strong><br />

must<br />

be<br />

configured<br />

to:<br />

v<br />

Recognize<br />

and<br />

intercept<br />

the<br />

login<br />

<strong>for</strong>m<br />

v<br />

Fill<br />

in<br />

the<br />

appropriate<br />

authentication<br />

data<br />

The<br />

administrator<br />

enables<br />

<strong>for</strong>ms<br />

single<br />

sign-on<br />

by:<br />

v<br />

Creating<br />

a<br />

configuration<br />

file<br />

to<br />

specify<br />

how<br />

the<br />

login<br />

<strong>for</strong>m<br />

is<br />

to<br />

be<br />

recognized,<br />

completed,<br />

and<br />

processed<br />

v<br />

Enable<br />

<strong>for</strong>ms<br />

single<br />

sign-on<br />

by<br />

configuring<br />

the<br />

appropriate<br />

junction<br />

with<br />

the<br />

–S<br />

option<br />

(which<br />

specifies<br />

the<br />

location<br />

of<br />

the<br />

configuration<br />

file)<br />

Forms<br />

single<br />

sign-on<br />

process<br />

flow<br />

The<br />

following<br />

scenario<br />

assumes<br />

that<br />

<strong>WebSEAL</strong><br />

has<br />

already<br />

authenticated<br />

the<br />

user.<br />

326<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!