10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Deploying<br />

the<br />

attribute<br />

retrieval<br />

service<br />

These<br />

installation<br />

instructions<br />

assume<br />

that<br />

WebSphere<br />

Application<br />

Server,<br />

<strong>WebSEAL</strong>,<br />

and<br />

the<br />

attribute<br />

retrieval<br />

service<br />

are<br />

on<br />

the<br />

same<br />

computer.<br />

Per<strong>for</strong>m<br />

the<br />

following<br />

tasks<br />

to<br />

deploy<br />

the<br />

attribute<br />

retrieval<br />

service<br />

with<br />

WebSphere<br />

Application<br />

Server.<br />

1.<br />

The<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

attribute<br />

retrieval<br />

service<br />

is<br />

a<br />

separately<br />

installable<br />

package.<br />

Install<br />

the<br />

attribute<br />

retrieval<br />

service<br />

on<br />

the<br />

same<br />

system<br />

as<br />

WebSphere<br />

Application<br />

Server.<br />

Follow<br />

the<br />

instructions<br />

in<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

Base<br />

Installation<br />

Guide.<br />

2.<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

provides<br />

a<br />

script<br />

that<br />

programmatically<br />

deploys<br />

the<br />

attribute<br />

retrieval<br />

service<br />

into<br />

the<br />

WebSphere<br />

Application<br />

Server<br />

environment.<br />

Follow<br />

the<br />

instructions<br />

in<br />

the<br />

Readme<br />

file.<br />

UNIX<br />

Readme<br />

/opt/pdwebars/Readme.deploy<br />

Script<br />

/opt/pdwebars/Deploy.sh<br />

Windows<br />

Readme<br />

C:\Program<br />

Files\<strong>Tivoli</strong>\AMWebARS\Readme.deploy<br />

Batch<br />

file<br />

C:\Program<br />

Files\<strong>Tivoli</strong>\AMWebARS\Deploy.bat<br />

Per<strong>for</strong>m<br />

the<br />

following<br />

tasks<br />

to<br />

configure<br />

<strong>WebSEAL</strong><br />

to<br />

use<br />

the<br />

attribute<br />

retrieval<br />

service.<br />

1.<br />

In<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file,<br />

specify<br />

the<br />

identification<br />

name<br />

(ID)<br />

of<br />

the<br />

attribute<br />

retrieval<br />

service<br />

that<br />

is<br />

queried<br />

when<br />

missing<br />

ADI<br />

is<br />

detected<br />

during<br />

a<br />

rules<br />

evaluation.<br />

In<br />

this<br />

case,<br />

the<br />

attribute<br />

retrieval<br />

service<br />

is<br />

specified:<br />

[aznapi-configuration]<br />

dynamic-adi-entitlement-services<br />

=<br />

AMWebARS_A<br />

2.<br />

In<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file,<br />

use<br />

the<br />

service<br />

ID<br />

<strong>for</strong><br />

the<br />

configured<br />

attribute<br />

retrieval<br />

service<br />

as<br />

a<br />

parameter<br />

to<br />

specify<br />

the<br />

appropriate<br />

built-in<br />

library<br />

that<br />

<strong>for</strong>mats<br />

out-bound<br />

ADI<br />

requests<br />

and<br />

interprets<br />

incoming<br />

responses:<br />

For<br />

example:<br />

[aznapi-entitlement-services]<br />

AMWebARS_A<br />

=<br />

azn_ent_amwebars<br />

3.<br />

In<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file,<br />

specify<br />

the<br />

URL<br />

to<br />

the<br />

attribute<br />

retrieval<br />

service<br />

located<br />

in<br />

the<br />

WebSphere<br />

environment.<br />

For<br />

a<br />

TCP<br />

connection:<br />

[amwebars]<br />

service-url<br />

=<br />

http://websphere_hostname:websphere_port<br />

\<br />

/amwebars/amwebars/ServiceToIServicePortAdapter<br />

4.<br />

Restart<br />

<strong>WebSEAL</strong>.<br />

Chapter<br />

13.<br />

Authorization<br />

decision<br />

in<strong>for</strong>mation<br />

retrieval<br />

365

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!