10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

including<br />

tracking<br />

CGI<br />

types,<br />

compiling<br />

lists<br />

of<br />

icons<br />

<strong>for</strong><br />

indexing,<br />

defining<br />

and<br />

sizing<br />

content<br />

caches,<br />

defining<br />

MIME<br />

types,<br />

and<br />

listing<br />

content<br />

encodings.<br />

Examples<br />

of<br />

stanzas<br />

that<br />

use<br />

lists<br />

are<br />

[filter-url],<br />

[filter-events],<br />

and<br />

[content-mime-types].<br />

There<br />

are<br />

additional<br />

stanzas<br />

that<br />

support<br />

lists.<br />

Consult<br />

the<br />

stanza<br />

descriptions<br />

in<br />

this<br />

chapter<br />

<strong>for</strong><br />

complete<br />

in<strong>for</strong>mation.<br />

File<br />

names<br />

Some<br />

values<br />

are<br />

file<br />

names.<br />

For<br />

each<br />

stanza<br />

entry<br />

that<br />

expects<br />

a<br />

file<br />

name<br />

as<br />

a<br />

value,<br />

the<br />

description<br />

of<br />

the<br />

stanza<br />

entry<br />

specifies<br />

which<br />

of<br />

the<br />

following<br />

constructs<br />

are<br />

valid:<br />

v<br />

File<br />

name<br />

No<br />

directory<br />

path<br />

included.<br />

v<br />

Relative<br />

file<br />

name<br />

A<br />

directory<br />

path<br />

is<br />

allowed,<br />

but<br />

not<br />

mandatory.<br />

These<br />

files<br />

typically<br />

are<br />

expected<br />

to<br />

be<br />

relative<br />

to<br />

the<br />

location<br />

of<br />

a<br />

standard<br />

<strong>WebSEAL</strong><br />

directory,<br />

such<br />

as<br />

the<br />

<strong>WebSEAL</strong><br />

server-root<br />

or<br />

the<br />

document<br />

root,<br />

doc-root.<br />

The<br />

stanza<br />

entry<br />

<strong>for</strong><br />

each<br />

relative<br />

lists<br />

the<br />

root<br />

directory<br />

to<br />

which<br />

the<br />

file<br />

name<br />

is<br />

relative.<br />

v<br />

Fully<br />

qualified<br />

(<br />

absolute)<br />

path<br />

An<br />

absolute<br />

directory<br />

path<br />

is<br />

required.<br />

Note:<br />

Some<br />

stanza<br />

entries<br />

allow<br />

more<br />

than<br />

one<br />

of<br />

the<br />

above<br />

choices.<br />

The<br />

set<br />

of<br />

characters<br />

permitted<br />

in<br />

a<br />

file<br />

name<br />

is<br />

determined<br />

by<br />

the<br />

file<br />

system<br />

and<br />

by<br />

the<br />

local<br />

codeset.<br />

<strong>WebSEAL</strong><br />

does<br />

not<br />

impose<br />

additional<br />

limitations<br />

on<br />

the<br />

set<br />

of<br />

allowable<br />

characters<br />

in<br />

a<br />

file<br />

name.<br />

For<br />

Windows,<br />

file<br />

names<br />

cannot<br />

have<br />

these<br />

characters:<br />

a<br />

backslash<br />

(\),<br />

a<br />

colon<br />

(:),<br />

a<br />

question<br />

mark<br />

(?),<br />

or<br />

double<br />

quotation<br />

marks<br />

(″).<br />

Integers<br />

Many<br />

stanza<br />

entries<br />

expect<br />

the<br />

value<br />

<strong>for</strong><br />

the<br />

entry<br />

to<br />

be<br />

expressed<br />

as<br />

an<br />

integer.<br />

v<br />

Stanza<br />

entries<br />

that<br />

take<br />

an<br />

integer<br />

value<br />

expect<br />

integer<br />

values<br />

within<br />

a<br />

valid<br />

range.<br />

The<br />

range<br />

is<br />

described<br />

in<br />

terms<br />

of<br />

a<br />

minimum<br />

value<br />

and<br />

a<br />

maximum<br />

value.<br />

For<br />

example,<br />

in<br />

the<br />

[logging]<br />

stanza,<br />

the<br />

logflush<br />

stanza<br />

entry<br />

has<br />

a<br />

minimum<br />

value<br />

of<br />

1<br />

second<br />

and<br />

a<br />

maximum<br />

value<br />

of<br />

600<br />

seconds.<br />

v<br />

For<br />

some<br />

entries,<br />

the<br />

integer<br />

value<br />

must<br />

be<br />

positive,<br />

and<br />

the<br />

minimum<br />

value<br />

is<br />

1.<br />

For<br />

other<br />

entries,<br />

a<br />

minimum<br />

integer<br />

value<br />

of<br />

0<br />

is<br />

allowed.<br />

Use<br />

caution<br />

when<br />

setting<br />

an<br />

integer<br />

value<br />

to<br />

0.<br />

For<br />

some<br />

entries,<br />

an<br />

integer<br />

value<br />

of<br />

0<br />

disables<br />

the<br />

feature<br />

controlled<br />

by<br />

the<br />

stanza<br />

entry.<br />

For<br />

example,<br />

in<br />

the<br />

[junction]<br />

stanza,<br />

the<br />

entry<br />

max-webseal-header-size<br />

limits<br />

the<br />

maximum<br />

size,<br />

in<br />

bytes,<br />

of<br />

HTTP<br />

headers<br />

generated<br />

by<br />

the<br />

<strong>WebSEAL</strong><br />

server.<br />

A<br />

value<br />

of<br />

zero<br />

(0)<br />

disables<br />

this<br />

support<br />

<strong>for</strong><br />

limiting<br />

header<br />

size.<br />

v<br />

For<br />

some<br />

entries<br />

requiring<br />

integer<br />

values,<br />

<strong>WebSEAL</strong><br />

does<br />

not<br />

impose<br />

an<br />

upper<br />

limit<br />

on<br />

the<br />

maximum<br />

number<br />

allowed.<br />

For<br />

example,<br />

there<br />

is<br />

typically<br />

no<br />

maximum<br />

<strong>for</strong><br />

timeout-related<br />

values,<br />

such<br />

as<br />

client-connect-timeout<br />

in<br />

the<br />

[server]<br />

stanza.<br />

For<br />

this<br />

type<br />

of<br />

entry,<br />

the<br />

maximum<br />

number<br />

is<br />

limited<br />

only<br />

by<br />

the<br />

size<br />

of<br />

memory<br />

allocated<br />

<strong>for</strong><br />

an<br />

integer<br />

data<br />

type.<br />

This<br />

number<br />

can<br />

vary<br />

based<br />

on<br />

operating<br />

system<br />

type.<br />

For<br />

systems<br />

that<br />

allocate<br />

4<br />

bytes<br />

<strong>for</strong><br />

an<br />

integer,<br />

this<br />

value<br />

is<br />

2147483647.<br />

380<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!