10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

v<br />

Entries<br />

in<br />

the<br />

configuration<br />

file<br />

should<br />

be<br />

ASCII<br />

characters.<br />

<strong>WebSEAL</strong><br />

does<br />

not<br />

expect<br />

to<br />

read<br />

non-ASCII<br />

characters,<br />

such<br />

as<br />

those<br />

supported<br />

by<br />

multi-byte<br />

locales,<br />

in<br />

the<br />

values<br />

<strong>for</strong><br />

configuration<br />

file<br />

entries.<br />

Default<br />

values<br />

v<br />

Many<br />

values<br />

are<br />

created<br />

or<br />

modified<br />

only<br />

by<br />

using<br />

configuration<br />

programs.<br />

You<br />

should<br />

not<br />

manually<br />

edit<br />

these<br />

stanzas<br />

or<br />

values.<br />

v<br />

Some<br />

values<br />

are<br />

filled<br />

in<br />

automatically<br />

during<br />

<strong>WebSEAL</strong><br />

configuration.<br />

These<br />

values<br />

are<br />

needed<br />

<strong>for</strong><br />

the<br />

initialization<br />

of<br />

the<br />

server<br />

after<br />

the<br />

configuration.<br />

v<br />

The<br />

default<br />

values<br />

<strong>for</strong><br />

a<br />

stanza<br />

entry<br />

might<br />

be<br />

different,<br />

depending<br />

on<br />

the<br />

server<br />

configuration.<br />

Some<br />

stanza<br />

entries<br />

are<br />

not<br />

applicable<br />

to<br />

certain<br />

configurations<br />

and<br />

are<br />

omitted<br />

from<br />

the<br />

default<br />

configuration<br />

file<br />

<strong>for</strong><br />

this<br />

server.<br />

Strings<br />

Some<br />

values<br />

accept<br />

a<br />

string<br />

value.<br />

When<br />

you<br />

manually<br />

edit<br />

the<br />

configuration<br />

file,<br />

use<br />

the<br />

following<br />

guidelines<br />

to<br />

change<br />

configuration<br />

settings<br />

that<br />

require<br />

a<br />

string:<br />

v<br />

String<br />

values<br />

are<br />

expected<br />

to<br />

be<br />

characters<br />

that<br />

are<br />

part<br />

of<br />

the<br />

local<br />

codeset.<br />

v<br />

Some<br />

<strong>WebSEAL</strong><br />

strings<br />

impose<br />

additional<br />

or<br />

different<br />

restrictions<br />

on<br />

the<br />

set<br />

of<br />

allowable<br />

string<br />

characters.<br />

For<br />

example,<br />

many<br />

strings<br />

are<br />

restricted<br />

to<br />

ASCII<br />

characters.<br />

The<br />

restrictions<br />

applicable<br />

to<br />

each<br />

string<br />

are<br />

listed<br />

under<br />

the<br />

appropriate<br />

stanza<br />

entry<br />

discussion<br />

later<br />

in<br />

this<br />

chapter.<br />

Consult<br />

each<br />

stanza<br />

entry<br />

description<br />

<strong>for</strong><br />

any<br />

additional<br />

restrictions.<br />

v<br />

Double<br />

quotation<br />

marks<br />

are<br />

sometimes,<br />

but<br />

not<br />

always,<br />

required<br />

if<br />

spaces<br />

or<br />

more<br />

than<br />

one<br />

word<br />

are<br />

used<br />

<strong>for</strong><br />

values.<br />

Refer<br />

to<br />

the<br />

descriptions<br />

or<br />

examples<br />

<strong>for</strong><br />

each<br />

stanza<br />

entry<br />

when<br />

in<br />

doubt.<br />

v<br />

The<br />

minimum<br />

and<br />

maximum<br />

lengths<br />

of<br />

user<br />

registry-related<br />

string<br />

values,<br />

if<br />

there<br />

are<br />

limits,<br />

are<br />

imposed<br />

by<br />

the<br />

underlying<br />

registry.<br />

For<br />

example,<br />

<strong>for</strong><br />

Active<br />

Directory<br />

the<br />

maximum<br />

length<br />

is<br />

256<br />

alphanumeric<br />

characters.<br />

Defined<br />

strings<br />

Some<br />

values<br />

accept<br />

a<br />

string<br />

value,<br />

but<br />

the<br />

value<br />

must<br />

be<br />

one<br />

of<br />

a<br />

set<br />

of<br />

defined<br />

strings.<br />

When<br />

you<br />

manually<br />

edit<br />

the<br />

configuration<br />

file,<br />

make<br />

sure<br />

that<br />

the<br />

string<br />

value<br />

you<br />

type<br />

matches<br />

one<br />

of<br />

the<br />

valid<br />

defined<br />

strings<br />

values.<br />

For<br />

example,<br />

the<br />

[ba]<br />

stanza<br />

in<br />

the<br />

authentication<br />

mechanisms<br />

section<br />

contains<br />

the<br />

following<br />

entry:<br />

ba-auth<br />

=<br />

{<br />

none<br />

|<br />

http<br />

|<br />

https<br />

|<br />

both<br />

}<br />

<strong>WebSEAL</strong><br />

expects<br />

the<br />

value<br />

of<br />

ba-auth<br />

to<br />

be<br />

either<br />

none<br />

or<br />

http<br />

or<br />

https<br />

or<br />

both.<br />

Any<br />

other<br />

value<br />

is<br />

invalid<br />

and<br />

will<br />

result<br />

in<br />

an<br />

error.<br />

Lists<br />

The<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

contains<br />

some<br />

stanzas<br />

that<br />

use<br />

stanza<br />

entries<br />

that<br />

do<br />

not<br />

have<br />

defined<br />

key<br />

names.<br />

The<br />

contents<br />

of<br />

these<br />

stanzas<br />

are<br />

called<br />

lists.<br />

Lists<br />

are<br />

configurable,<br />

and<br />

are<br />

specified<br />

by<br />

the<br />

administrator.<br />

Some<br />

lists<br />

are<br />

included<br />

by<br />

default<br />

and<br />

can<br />

be<br />

appended<br />

by<br />

the<br />

administrator.<br />

Other<br />

lists<br />

are<br />

empty<br />

be<br />

default<br />

and<br />

can<br />

be<br />

created<br />

by<br />

the<br />

administrator.<br />

Lists<br />

are<br />

used<br />

by<br />

<strong>WebSEAL</strong><br />

<strong>for</strong><br />

a<br />

number<br />

of<br />

purposes.<br />

<strong>WebSEAL</strong><br />

filters<br />

incoming<br />

data<br />

based<br />

on<br />

document<br />

type,<br />

event<br />

handler<br />

type,<br />

MIME<br />

type,<br />

and<br />

header<br />

request<br />

data.<br />

<strong>WebSEAL</strong><br />

also<br />

uses<br />

lists<br />

<strong>for</strong><br />

content<br />

management<br />

in<br />

a<br />

number<br />

of<br />

areas,<br />

Appendix<br />

A.<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

reference<br />

379

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!