10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

String<br />

that<br />

specifies<br />

the<br />

key<br />

label<br />

of<br />

the<br />

client<br />

personal<br />

certificate<br />

within<br />

the<br />

SSL<br />

key<br />

file.<br />

This<br />

key<br />

label<br />

is<br />

used<br />

to<br />

identify<br />

the<br />

client<br />

certificate<br />

that<br />

is<br />

presented<br />

to<br />

the<br />

LDAP<br />

server.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

A<br />

label<br />

is<br />

not<br />

required<br />

when<br />

one<br />

of<br />

the<br />

certificates<br />

in<br />

the<br />

keyfile<br />

has<br />

been<br />

identified<br />

as<br />

the<br />

default<br />

certificate.<br />

The<br />

decision<br />

whether<br />

to<br />

identify<br />

a<br />

certificate<br />

as<br />

the<br />

default<br />

was<br />

made<br />

previously<br />

by<br />

the<br />

LDAP<br />

administrator<br />

when<br />

configuring<br />

the<br />

LDAP<br />

server.<br />

The<br />

<strong>WebSEAL</strong><br />

configuration<br />

utility<br />

prompts<br />

the<br />

<strong>WebSEAL</strong><br />

administrator<br />

to<br />

supply<br />

a<br />

label.<br />

When<br />

the<br />

administrator<br />

knows<br />

that<br />

the<br />

certificate<br />

contained<br />

in<br />

the<br />

keyfile<br />

is<br />

the<br />

default<br />

certificate,<br />

the<br />

administrator<br />

does<br />

not<br />

have<br />

to<br />

specify<br />

a<br />

label.<br />

Example:<br />

ssl-keyfile-dn<br />

=<br />

"PD_LDAP"<br />

ssl-keyfile-pwd<br />

=<br />

password<br />

Password<br />

to<br />

access<br />

the<br />

SSL<br />

key<br />

file.<br />

The<br />

password<br />

associated<br />

with<br />

the<br />

default<br />

SSL<br />

keyfile<br />

is<br />

gsk4ikm<br />

Required<br />

only<br />

when<br />

SSL<br />

communication<br />

between<br />

<strong>WebSEAL</strong><br />

and<br />

LDAP<br />

is<br />

enabled,<br />

as<br />

specified<br />

in<br />

the<br />

ssl-enabled<br />

stanza<br />

entry.<br />

The<br />

<strong>WebSEAL</strong><br />

administrator<br />

specifies<br />

this<br />

password<br />

during<br />

<strong>WebSEAL</strong><br />

configuration.<br />

Example:<br />

ssl-keyfile-pwd<br />

=<br />

gsk4ikm<br />

auth-using-compare<br />

=<br />

{yes|true|no|false}<br />

Enables<br />

or<br />

disables<br />

authentication<br />

using<br />

password<br />

comparison.<br />

When<br />

disabled,<br />

authentication<br />

using<br />

LDAP<br />

bind<br />

is<br />

per<strong>for</strong>med.<br />

For<br />

those<br />

LDAP<br />

servers<br />

that<br />

allow<br />

it,<br />

a<br />

compare<br />

operation<br />

might<br />

per<strong>for</strong>m<br />

faster<br />

than<br />

a<br />

bind<br />

operation.<br />

Valid<br />

values<br />

are:<br />

yes|true<br />

A<br />

password<br />

compare<br />

operation<br />

is<br />

used<br />

to<br />

authenticate<br />

LDAP<br />

users.<br />

no|false<br />

A<br />

bind<br />

operation<br />

is<br />

used<br />

to<br />

authenticate<br />

LDAP<br />

users.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

The<br />

default<br />

value,<br />

when<br />

LDAP<br />

is<br />

enabled,<br />

is<br />

yes.<br />

Example:<br />

auth-using-compare<br />

=<br />

yes<br />

See<br />

also<br />

the<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong><br />

Per<strong>for</strong>mance<br />

Tuning<br />

Guide.<br />

default-policy-override-support<br />

=<br />

{yes|true|no|false}<br />

398<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!