10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Integer<br />

value<br />

indicating<br />

the<br />

maximum<br />

number<br />

of<br />

concurrent<br />

entries<br />

in<br />

the<br />

SSL<br />

cache.<br />

The<br />

minimum<br />

value<br />

is<br />

zero<br />

(0)<br />

which<br />

means<br />

that<br />

caching<br />

is<br />

unlimited.<br />

Entries<br />

between<br />

0<br />

and<br />

256<br />

are<br />

set<br />

to<br />

256.<br />

There<br />

is<br />

no<br />

maximum<br />

limit.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

When<br />

the<br />

stanza<br />

entry<br />

is<br />

not<br />

assigned<br />

a<br />

value,<br />

<strong>WebSEAL</strong><br />

uses<br />

a<br />

default<br />

value<br />

of<br />

0.<br />

The<br />

<strong>WebSEAL</strong><br />

configuration<br />

utility,<br />

however,<br />

assigns<br />

a<br />

default<br />

value<br />

of<br />

4096.<br />

Example:<br />

ssl-max-entries<br />

=<br />

4096<br />

See<br />

also<br />

the<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong><br />

Per<strong>for</strong>mance<br />

Tuning<br />

Guide.<br />

gsk-crl-cache-size<br />

=<br />

number_of_entries<br />

Integer<br />

value<br />

indicating<br />

the<br />

maximum<br />

number<br />

of<br />

entries<br />

in<br />

the<br />

GSKit<br />

CRL<br />

cache.<br />

Minimum<br />

value<br />

is<br />

0.<br />

A<br />

value<br />

of<br />

0<br />

means<br />

that<br />

no<br />

entries<br />

are<br />

cached.<br />

Neither<br />

<strong>WebSEAL</strong><br />

nor<br />

GSKit<br />

impose<br />

a<br />

maximum<br />

value<br />

on<br />

this<br />

cache.<br />

See<br />

the<br />

discussion<br />

on<br />

maximum<br />

values<br />

<strong>for</strong><br />

integers<br />

in<br />

“Guidelines<br />

<strong>for</strong><br />

configuring<br />

stanzas”<br />

on<br />

page<br />

378.<br />

See<br />

the<br />

Secure<br />

Socket<br />

Layer<br />

Introduction<br />

and<br />

iKeyman<br />

User’s<br />

Guide<br />

<strong>for</strong><br />

more<br />

in<strong>for</strong>mation<br />

on<br />

GSKit.<br />

See<br />

also<br />

the<br />

standards<br />

documents<br />

<strong>for</strong><br />

SSL<br />

V3<br />

and<br />

TLS<br />

V1<br />

(RFC<br />

2246)<br />

<strong>for</strong><br />

more<br />

in<strong>for</strong>mation<br />

on<br />

CRLs.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

Default<br />

value:<br />

0<br />

Example:<br />

gsk-crl-cache-size<br />

=<br />

0<br />

gsk-crl-cache-entry-lifetime<br />

=<br />

number_of_seconds<br />

Integer<br />

value<br />

specifying<br />

the<br />

lifetime<br />

timeout,<br />

in<br />

seconds,<br />

<strong>for</strong><br />

individual<br />

entries<br />

in<br />

the<br />

GSKit<br />

CRL<br />

cache.<br />

The<br />

minimum<br />

value<br />

is<br />

0.<br />

The<br />

maximum<br />

value<br />

is<br />

86400.<br />

Neither<br />

<strong>WebSEAL</strong><br />

nor<br />

GSKit<br />

impose<br />

a<br />

maximum<br />

value<br />

on<br />

the<br />

cache<br />

entry<br />

lifetime.<br />

See<br />

the<br />

discussion<br />

on<br />

maximum<br />

values<br />

<strong>for</strong><br />

integers<br />

in<br />

“Guidelines<br />

<strong>for</strong><br />

configuring<br />

stanzas”<br />

on<br />

page<br />

378.<br />

See<br />

the<br />

Secure<br />

Socket<br />

Layer<br />

Introduction<br />

and<br />

iKeyman<br />

User’s<br />

Guide<br />

<strong>for</strong><br />

more<br />

in<strong>for</strong>mation<br />

on<br />

GSKit.<br />

See<br />

also<br />

the<br />

standards<br />

documents<br />

<strong>for</strong><br />

SSL<br />

V3<br />

and<br />

TLS<br />

V1<br />

(RFC<br />

2246)<br />

<strong>for</strong><br />

more<br />

in<strong>for</strong>mation<br />

on<br />

CRLs.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

Default<br />

value:<br />

0<br />

Example:<br />

gsk-crl-cache-entry-lifetime<br />

=<br />

0<br />

crl-ldap-server<br />

=<br />

server_name<br />

Name<br />

of<br />

the<br />

LDAP<br />

server<br />

to<br />

be<br />

referenced<br />

<strong>for</strong><br />

Certificate<br />

Revocation<br />

List<br />

(CRL)<br />

checking<br />

during<br />

SSL<br />

authentication.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

There<br />

is<br />

no<br />

default<br />

value.<br />

Example:<br />

crl-ldap-server<br />

=<br />

surf.santacruz.ibm.com<br />

crl-ldap-server-port<br />

=<br />

port_number<br />

Appendix<br />

A.<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

reference<br />

409

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!