10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Note:<br />

If<br />

you<br />

use<br />

Web<br />

Portal<br />

<strong>Manager</strong><br />

to<br />

view<br />

the<br />

file<br />

and<br />

the<br />

file<br />

does<br />

not<br />

exist,<br />

the<br />

following<br />

error<br />

message<br />

is<br />

displayed:<br />

The<br />

dynurl<br />

configuration<br />

file<br />

/opt/pdweb/www-instance/lib/dynurl.conf<br />

cannot<br />

be<br />

opened<br />

<strong>for</strong><br />

reading.<br />

You<br />

can<br />

eliminate<br />

this<br />

error<br />

message<br />

by<br />

creating<br />

the<br />

file.<br />

To<br />

create<br />

the<br />

file,<br />

enter<br />

text<br />

in<br />

the<br />

text<br />

area<br />

and<br />

click<br />

Apply.<br />

Edit<br />

this<br />

file<br />

to<br />

modify<br />

these<br />

mappings.<br />

Entries<br />

in<br />

the<br />

file<br />

are<br />

of<br />

the<br />

<strong>for</strong>mat:<br />

object<br />

template<br />

You<br />

can<br />

use<br />

the<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

Web<br />

Portal<br />

<strong>Manager</strong><br />

to<br />

edit<br />

this<br />

file<br />

remotely.<br />

In<br />

Web<br />

Portal<br />

<strong>Manager</strong>,<br />

select<br />

the<br />

″Dynamic<br />

URL<br />

Files″<br />

link<br />

from<br />

the<br />

″<strong>WebSEAL</strong>″<br />

menu.<br />

The<br />

Dynamic<br />

URL<br />

page<br />

allows<br />

you<br />

to<br />

select<br />

a<br />

<strong>WebSEAL</strong><br />

server<br />

and<br />

then<br />

view,<br />

edit,<br />

and<br />

save<br />

the<br />

dynurl.conf<br />

configuration<br />

file<br />

located<br />

on<br />

that<br />

server.<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

uses<br />

a<br />

subset<br />

of<br />

UNIX<br />

shell<br />

pattern<br />

matching<br />

(including<br />

wildcards)<br />

to<br />

define<br />

the<br />

set<br />

of<br />

parameters<br />

that<br />

constitute<br />

one<br />

object<br />

in<br />

the<br />

object<br />

space.<br />

Any<br />

dynamic<br />

URL<br />

that<br />

matches<br />

those<br />

parameters<br />

is<br />

mapped<br />

to<br />

that<br />

object.<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

supports<br />

the<br />

following<br />

UNIX<br />

shell<br />

pattern-matching<br />

characters:<br />

Character<br />

Description<br />

\<br />

The<br />

character<br />

that<br />

follows<br />

the<br />

backslash<br />

is<br />

part<br />

of<br />

a<br />

special<br />

sequence.<br />

For<br />

example,<br />

\t<br />

is<br />

the<br />

TAB<br />

character.<br />

Can<br />

also<br />

act<br />

as<br />

an<br />

escape<br />

character.<br />

?<br />

Wildcard<br />

that<br />

matches<br />

a<br />

single<br />

character.<br />

For<br />

example,<br />

the<br />

string<br />

“abcde”<br />

is<br />

matched<br />

by<br />

the<br />

expression<br />

“ab?de”<br />

*<br />

Wildcard<br />

that<br />

matches<br />

zero<br />

or<br />

more<br />

characters.<br />

[]<br />

Defines<br />

a<br />

set<br />

of<br />

characters,<br />

from<br />

which<br />

any<br />

can<br />

match.<br />

For<br />

example,<br />

the<br />

string<br />

“abcde”<br />

is<br />

matched<br />

with<br />

the<br />

regular<br />

expression<br />

“ab[cty]de”.<br />

^<br />

Indicates<br />

a<br />

negation.<br />

For<br />

example,<br />

the<br />

expression<br />

[^ab]<br />

matches<br />

anything<br />

but<br />

the<br />

‘a’<br />

or<br />

‘b’<br />

characters.<br />

The<br />

following<br />

example<br />

illustrates<br />

the<br />

<strong>for</strong>m<br />

of<br />

a<br />

dynamic<br />

URL<br />

that<br />

per<strong>for</strong>ms<br />

credit<br />

balance<br />

lookup:<br />

http://server-name/home-bank/owa/acct.bal?acc=<br />

The<br />

object<br />

that<br />

represents<br />

this<br />

dynamic<br />

URL<br />

would<br />

appear<br />

as<br />

follows:<br />

http://server-name/home-bank/owa/acct.bal?acc=*<br />

Careful<br />

examination<br />

of<br />

the<br />

dynamic<br />

URL<br />

in<br />

this<br />

example<br />

shows<br />

that<br />

it<br />

describes<br />

a<br />

specific<br />

account<br />

number.<br />

The<br />

object<br />

<strong>for</strong><br />

account<br />

balances<br />

at<br />

home-bank<br />

shows<br />

that<br />

the<br />

ACL<br />

and<br />

POP<br />

permissions<br />

apply<br />

to<br />

any<br />

account,<br />

because<br />

the<br />

last<br />

portion<br />

of<br />

the<br />

entry<br />

(acc=*)<br />

uses<br />

the<br />

asterisk<br />

wildcard<br />

which<br />

matches<br />

all<br />

characters.<br />

The<br />

following<br />

figure<br />

illustrates<br />

a<br />

complete<br />

scenario<br />

of<br />

a<br />

specific<br />

dynamic<br />

URL<br />

mapped<br />

to<br />

a<br />

specific<br />

protected<br />

object:<br />

348<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!