10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Active<br />

Directory<br />

domain<br />

name<br />

system<br />

(DNS)<br />

host<br />

name.<br />

The<br />

value<br />

is<br />

filled<br />

in<br />

automatically,<br />

based<br />

on<br />

in<strong>for</strong>mation<br />

supplied<br />

during<br />

the<br />

runtime<br />

configuration.<br />

The<br />

hostname<br />

is<br />

an<br />

alphanumeric,<br />

non-case<br />

sensitive<br />

string.<br />

The<br />

dot<br />

(.)<br />

cannot<br />

be<br />

the<br />

last<br />

character<br />

of<br />

the<br />

host<br />

name.<br />

The<br />

maximum<br />

string<br />

length<br />

<strong>for</strong><br />

the<br />

Active<br />

Directory<br />

user<br />

registry<br />

is<br />

256<br />

alphanumeric<br />

characters.<br />

This<br />

stanza<br />

entry<br />

is<br />

required<br />

when<br />

your<br />

user<br />

registry<br />

is<br />

Microsoft<br />

Active<br />

Directory.<br />

There<br />

is<br />

no<br />

default<br />

value.<br />

Example:<br />

hostname<br />

=<br />

adserver.tivoli.com<br />

domain<br />

=<br />

root_domain_name<br />

Active<br />

Directory<br />

root<br />

(primary)<br />

domain.<br />

The<br />

value<br />

is<br />

filled<br />

in<br />

automatically,<br />

based<br />

on<br />

in<strong>for</strong>mation<br />

supplied<br />

during<br />

the<br />

runtime<br />

configuration.<br />

The<br />

root_domain_name<br />

is<br />

an<br />

alphanumeric,<br />

non-case<br />

sensitive<br />

string.<br />

The<br />

maximum<br />

length<br />

<strong>for</strong><br />

the<br />

domain<br />

name<br />

is<br />

user<br />

registry<br />

dependent.<br />

For<br />

Active<br />

Directory<br />

that<br />

maximum<br />

length<br />

is<br />

256<br />

alphanumeric<br />

characters.<br />

This<br />

stanza<br />

entry<br />

is<br />

required<br />

when<br />

multi-domain<br />

=<br />

true.<br />

There<br />

is<br />

no<br />

default<br />

behavior.<br />

Example:<br />

domain<br />

=<br />

dc=tivoli,dc=com<br />

useEncryption<br />

=<br />

{true|false}<br />

Indication<br />

of<br />

whether<br />

encryption<br />

communication<br />

to<br />

Active<br />

Directory<br />

is<br />

being<br />

used.<br />

This<br />

value<br />

is<br />

filled<br />

in<br />

automatically,<br />

based<br />

on<br />

in<strong>for</strong>mation<br />

supplied<br />

during<br />

the<br />

runtime<br />

configuration.<br />

Valid<br />

values:<br />

true<br />

Enables<br />

encryption<br />

communication.<br />

false<br />

Disables<br />

encryption<br />

communication.<br />

This<br />

stanza<br />

entry<br />

is<br />

required<br />

when<br />

your<br />

user<br />

registry<br />

is<br />

Microsoft<br />

Active<br />

Directory.<br />

There<br />

is<br />

no<br />

default<br />

behavior.<br />

Example:<br />

useEncryption<br />

=<br />

false<br />

bind-id<br />

=<br />

ad_id<br />

Active<br />

Directory<br />

administrator<br />

or<br />

user<br />

log-in<br />

identity<br />

that<br />

is<br />

used<br />

to<br />

bind<br />

(sign<br />

on)<br />

to<br />

the<br />

registry<br />

server.<br />

If<br />

the<br />

ID<br />

belongs<br />

to<br />

a<br />

user<br />

rather<br />

than<br />

an<br />

administrator,<br />

the<br />

Active<br />

Directory<br />

user<br />

must<br />

have<br />

enough<br />

privileges<br />

to<br />

update<br />

and<br />

modify<br />

data<br />

in<br />

the<br />

user<br />

registry.<br />

The<br />

ad_id<br />

value<br />

is<br />

an<br />

alphanumeric,<br />

non-case<br />

sensitive<br />

string.<br />

The<br />

minimum<br />

and<br />

maximum<br />

lengths<br />

of<br />

the<br />

ID,<br />

if<br />

there<br />

are<br />

limits,<br />

are<br />

imposed<br />

by<br />

the<br />

underlying<br />

registry.<br />

For<br />

Active<br />

Directory<br />

the<br />

maximum<br />

length<br />

is<br />

256<br />

alphanumeric<br />

characters.<br />

This<br />

value<br />

is<br />

filled<br />

in<br />

automatically,<br />

based<br />

on<br />

in<strong>for</strong>mation<br />

supplied<br />

during<br />

server<br />

configuration.<br />

Whenever<br />

you<br />

change<br />

this<br />

value<br />

after<br />

the<br />

configuration<br />

is<br />

completed,<br />

a<br />

conflict<br />

might<br />

occur.<br />

This<br />

stanza<br />

entry<br />

is<br />

required<br />

when<br />

your<br />

user<br />

registry<br />

is<br />

Microsoft<br />

Active<br />

Directory.<br />

The<br />

default<br />

value<br />

is<br />

generated;<br />

do<br />

not<br />

change<br />

it.<br />

Example:<br />

bind-id<br />

=<br />

adpdadmin<br />

Appendix<br />

A.<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

reference<br />

401

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!