10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Indicates<br />

whether<br />

automatic<br />

refresh<br />

of<br />

the<br />

SSL<br />

certificate<br />

and<br />

the<br />

key<br />

database<br />

file<br />

password<br />

occur.<br />

Valid<br />

values<br />

are:<br />

yes<br />

Automatic<br />

refresh<br />

is<br />

enabled.<br />

When<br />

enabled,<br />

the<br />

certificate<br />

and<br />

password<br />

are<br />

regenerated<br />

if<br />

either<br />

is<br />

in<br />

danger<br />

of<br />

expiration<br />

(less<br />

than<br />

half<br />

the<br />

time<br />

left).<br />

This<br />

value<br />

is<br />

the<br />

default<br />

value.<br />

no<br />

Turn<br />

off<br />

automatic<br />

certificate<br />

and<br />

password<br />

refresh.<br />

This<br />

stanza<br />

entry<br />

is<br />

required<br />

only<br />

when<br />

SSL<br />

is<br />

enabled.<br />

Default<br />

value:<br />

yes<br />

Example:<br />

ssl-auto-refresh<br />

=<br />

yes<br />

ssl-listening-port<br />

=<br />

{0|port_number}<br />

TCP<br />

port<br />

to<br />

listen<br />

on<br />

<strong>for</strong><br />

incoming<br />

requests.<br />

Valid<br />

values<br />

are:<br />

0<br />

Disables<br />

listening.<br />

The<br />

default<br />

value<br />

is<br />

0<br />

if<br />

not<br />

specified<br />

during<br />

configuration.<br />

port_number<br />

Enables<br />

listening<br />

at<br />

the<br />

specified<br />

port<br />

number.<br />

The<br />

valid<br />

range<br />

<strong>for</strong><br />

port<br />

numbers<br />

is<br />

any<br />

positive<br />

number<br />

that<br />

is<br />

allowed<br />

by<br />

TCP/IP<br />

and<br />

is<br />

not<br />

currently<br />

being<br />

used<br />

by<br />

another<br />

application.<br />

This<br />

stanza<br />

entry<br />

is<br />

required<br />

only<br />

when<br />

SSL<br />

is<br />

enabled.<br />

The<br />

default<br />

value<br />

is<br />

supplied<br />

by<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

utility,<br />

and<br />

is<br />

dependent<br />

on<br />

the<br />

available<br />

TCP/IP<br />

ports.<br />

A<br />

typical<br />

value<br />

during<br />

<strong>WebSEAL</strong><br />

configuration<br />

is<br />

7234.<br />

Example:<br />

ssl-listening-port<br />

=<br />

7234<br />

ssl-pwd-life<br />

=<br />

number_of_days<br />

Password<br />

lifetime<br />

<strong>for</strong><br />

the<br />

key<br />

database<br />

file,<br />

specified<br />

in<br />

the<br />

number<br />

of<br />

days.<br />

For<br />

automatic<br />

password<br />

renewal,<br />

the<br />

value<br />

<strong>for</strong><br />

the<br />

lifetime<br />

of<br />

a<br />

password<br />

is<br />

controlled<br />

by<br />

the<br />

number_of_days<br />

value<br />

when<br />

the<br />

server<br />

is<br />

started.<br />

Note:<br />

If<br />

a<br />

certificate<br />

and<br />

the<br />

password<br />

to<br />

the<br />

keyring<br />

database<br />

file<br />

containing<br />

that<br />

certificate<br />

are<br />

both<br />

expired,<br />

then<br />

the<br />

password<br />

must<br />

be<br />

refreshed<br />

first.<br />

Valid<br />

values<br />

<strong>for</strong><br />

the<br />

number_of_days<br />

is<br />

from<br />

1<br />

to<br />

7,299<br />

days.<br />

This<br />

stanza<br />

entry<br />

is<br />

required<br />

only<br />

if<br />

SSL<br />

is<br />

enabled.<br />

Default<br />

value:<br />

183<br />

Example:<br />

ssl-pwd-life<br />

=<br />

183<br />

ssl-authn-type<br />

=<br />

authentication_type<br />

Type<br />

of<br />

authentication.<br />

This<br />

stanza<br />

entry<br />

is<br />

required<br />

only<br />

when<br />

SSL<br />

is<br />

enabled.<br />

Default<br />

value:<br />

certificate<br />

Example:<br />

ssl-authn-type<br />

=<br />

certificate<br />

412<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!