10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Secure<br />

Socket<br />

Layer<br />

[ssl]<br />

stanza<br />

webseal-cert-keyfile<br />

=<br />

fully_qualified_path<br />

Path<br />

name<br />

to<br />

the<br />

<strong>WebSEAL</strong><br />

certificate<br />

keyfile.<br />

This<br />

is<br />

the<br />

certificate<br />

that<br />

<strong>WebSEAL</strong><br />

exchanges<br />

with<br />

browsers<br />

when<br />

negotiating<br />

SSL<br />

sessions.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

This<br />

path<br />

is<br />

set<br />

during<br />

<strong>WebSEAL</strong><br />

configuration.<br />

The<br />

path<br />

consists<br />

of<br />

the<br />

<strong>WebSEAL</strong><br />

installation<br />

directory<br />

plus:<br />

www-instance_name/certs/pdsrv.kdb.<br />

Example:<br />

webseal-cert-keyfile<br />

=<br />

C:/Program<br />

Files/<strong>Tivoli</strong>/PDWeb/www-web1/certs/pdsrv.kdb<br />

This<br />

path<br />

is<br />

typically<br />

not<br />

modified<br />

by<br />

the<br />

<strong>WebSEAL</strong><br />

administrator<br />

after<br />

initial<br />

<strong>WebSEAL</strong><br />

configuration.<br />

webseal-cert-keyfile-stash<br />

=<br />

fully_qualified_path<br />

Name<br />

of<br />

the<br />

file<br />

containing<br />

an<br />

obfuscated<br />

version<br />

of<br />

the<br />

password<br />

used<br />

to<br />

protect<br />

private<br />

keys<br />

in<br />

the<br />

keyfile.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

This<br />

path<br />

is<br />

set<br />

during<br />

<strong>WebSEAL</strong><br />

configuration.<br />

The<br />

path<br />

consists<br />

of<br />

the<br />

<strong>WebSEAL</strong><br />

installation<br />

directory<br />

plus:<br />

www-instance_name/certs/pdsrv.sth.<br />

Example:<br />

webseal-cert-keyfile-stash<br />

=<br />

C:/Program<br />

Files/<strong>Tivoli</strong>/PDWeb/www-web1/certs/pdsrv.sth<br />

webseal-cert-keyfile-pwd<br />

=<br />

password<br />

Password<br />

used<br />

to<br />

protect<br />

private<br />

keys<br />

in<br />

<strong>WebSEAL</strong><br />

certificate<br />

file.<br />

When<br />

this<br />

stanza<br />

entry<br />

is<br />

assigned<br />

a<br />

value,<br />

that<br />

value<br />

is<br />

used<br />

instead<br />

of<br />

any<br />

password<br />

that<br />

is<br />

contained<br />

in<br />

the<br />

stash<br />

file<br />

specified<br />

by<br />

webseal-cert-keyfile-stash.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

This<br />

stanza<br />

entry<br />

stores<br />

the<br />

password<br />

in<br />

plain<br />

text.<br />

For<br />

optimum<br />

security<br />

practice,<br />

use<br />

of<br />

the<br />

stash<br />

file<br />

is<br />

recommended.<br />

There<br />

is<br />

no<br />

default<br />

value.<br />

Example:<br />

webseal-cert-keyfile-pwd<br />

=<br />

j73R45huu<br />

webseal-cert-keyfile-label<br />

=<br />

label_name<br />

String<br />

specifying<br />

a<br />

label<br />

to<br />

use<br />

<strong>for</strong><br />

<strong>WebSEAL</strong><br />

certificate<br />

keyfile.<br />

When<br />

this<br />

is<br />

not<br />

specified,<br />

the<br />

default<br />

label<br />

is<br />

used.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional,<br />

but<br />

is<br />

set<br />

by<br />

default<br />

during<br />

<strong>WebSEAL</strong><br />

configuration.<br />

Default<br />

value:<br />

<strong>WebSEAL</strong>-Test-Only<br />

Example:<br />

webseal-cert-keyfile-label<br />

=<br />

<strong>WebSEAL</strong>-Test-Only<br />

ssl-keyfile<br />

=<br />

fully_qualified_path<br />

406<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!