10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

String<br />

specifying<br />

the<br />

path<br />

to<br />

the<br />

keystore<br />

<strong>WebSEAL</strong><br />

uses<br />

<strong>for</strong><br />

communicating<br />

with<br />

other<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

servers<br />

over<br />

SSL.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

The<br />

default<br />

value<br />

is<br />

set<br />

during<br />

<strong>WebSEAL</strong><br />

configuration.<br />

The<br />

<strong>WebSEAL</strong><br />

installation<br />

directory<br />

path<br />

is<br />

combined<br />

with<br />

the<br />

following<br />

path:<br />

keytabs/webseald.kdb<br />

Example:<br />

ssl-keyfile<br />

=<br />

C:/Program<br />

Files/<strong>Tivoli</strong>/PDWeb/keytabs/webseald.kdb<br />

This<br />

stanza<br />

entry<br />

is<br />

typically<br />

modified<br />

only<br />

by<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

utility.<br />

ssl-keyfile-pwd<br />

=<br />

password<br />

String<br />

containing<br />

the<br />

password<br />

to<br />

protect<br />

the<br />

private<br />

keys<br />

in<br />

the<br />

SSL<br />

keyfile.<br />

When<br />

this<br />

stanza<br />

entry<br />

is<br />

assigned<br />

a<br />

value,<br />

that<br />

value<br />

is<br />

used<br />

instead<br />

of<br />

any<br />

password<br />

that<br />

is<br />

contained<br />

in<br />

the<br />

stash<br />

file<br />

specified<br />

by<br />

ssl-keyfile-stash.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

This<br />

stanza<br />

entry<br />

stores<br />

the<br />

password<br />

in<br />

plain<br />

text.<br />

For<br />

optimum<br />

security<br />

practice,<br />

use<br />

of<br />

the<br />

ssl-keyfile-stash<br />

is<br />

recommended.<br />

There<br />

is<br />

no<br />

default<br />

value.<br />

Example:<br />

ssl-keyfile-pwd<br />

=<br />

myPassw0rd<br />

This<br />

stanza<br />

entry<br />

is<br />

typically<br />

modified<br />

only<br />

by<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

utility.<br />

ssl-keyfile-stash<br />

=<br />

fully_qualified_path<br />

Name<br />

of<br />

the<br />

file<br />

containing<br />

an<br />

obfuscated<br />

version<br />

of<br />

the<br />

password<br />

used<br />

to<br />

protect<br />

private<br />

keys<br />

in<br />

the<br />

SSL<br />

keyfile.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

This<br />

path<br />

is<br />

set<br />

during<br />

<strong>WebSEAL</strong><br />

configuration.<br />

The<br />

path<br />

consists<br />

of<br />

the<br />

<strong>WebSEAL</strong><br />

installation<br />

directory<br />

plus:<br />

keytabs/webseald.sth.<br />

Example:<br />

ssl-keyfile-stash<br />

=<br />

C:/Program<br />

Files/<strong>Tivoli</strong>/PDWeb/keytabs/webseald.sth<br />

This<br />

stanza<br />

entry<br />

is<br />

typically<br />

modified<br />

only<br />

by<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

utility.<br />

ssl-keyfile-label<br />

=<br />

label_name<br />

String<br />

containing<br />

a<br />

label<br />

<strong>for</strong><br />

the<br />

SSL<br />

certificate<br />

keyfile.<br />

When<br />

this<br />

label<br />

is<br />

not<br />

specified,<br />

the<br />

default<br />

label<br />

is<br />

used.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional,<br />

but<br />

is<br />

assigned<br />

during<br />

<strong>WebSEAL</strong><br />

configuration.<br />

Default<br />

value:<br />

PD<br />

Server<br />

Example:<br />

ssl-keyfile-label<br />

=<br />

PD<br />

Server<br />

This<br />

stanza<br />

entry<br />

is<br />

typically<br />

modified<br />

only<br />

by<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

utility.<br />

disable-ssl-v2<br />

=<br />

{yes|no}<br />

Appendix<br />

A.<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

reference<br />

407

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!