10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Specifies<br />

how<br />

to<br />

handle<br />

certificates<br />

from<br />

HTTPS<br />

clients.<br />

Options<br />

are:<br />

never<br />

Never<br />

request<br />

a<br />

client<br />

certificate<br />

required<br />

Always<br />

request<br />

a<br />

client<br />

certificate.<br />

Do<br />

not<br />

accept<br />

the<br />

connection<br />

if<br />

the<br />

client<br />

does<br />

not<br />

present<br />

a<br />

certificate.<br />

When<br />

this<br />

value<br />

is<br />

set<br />

to<br />

required,<br />

all<br />

other<br />

authentication<br />

settings<br />

are<br />

ignored<br />

<strong>for</strong><br />

HTTPS<br />

clients.<br />

optional<br />

Always<br />

request<br />

a<br />

client<br />

certificate.<br />

If<br />

presented,<br />

use<br />

it.<br />

prompt_as_needed<br />

Do<br />

not<br />

prompt<br />

<strong>for</strong><br />

a<br />

client<br />

certificate<br />

until<br />

the<br />

client<br />

attempts<br />

to<br />

access<br />

a<br />

resource<br />

that<br />

requires<br />

certificate<br />

authentication.<br />

Note:<br />

When<br />

this<br />

value<br />

is<br />

set,<br />

ensure<br />

that<br />

the<br />

ssl-id-sessions<br />

key<br />

in<br />

the<br />

[ssl]<br />

stanza<br />

is<br />

set<br />

to<br />

no.<br />

When<br />

certificate<br />

authentication<br />

is<br />

enabled,<br />

you<br />

must<br />

also<br />

configure<br />

an<br />

appropriate<br />

authentication<br />

library<br />

by<br />

setting<br />

a<br />

key=value<br />

pair<br />

in<br />

the<br />

[authentication-mechanisms]<br />

stanza.<br />

See<br />

“Authentication<br />

libraries”<br />

on<br />

page<br />

419<br />

<strong>for</strong><br />

more<br />

in<strong>for</strong>mation.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

Default<br />

value:<br />

never<br />

Example<br />

accept-client-certs<br />

=<br />

never<br />

cert-cache-max-entries<br />

=<br />

number_of_entries<br />

Maximum<br />

number<br />

of<br />

concurrent<br />

entries<br />

in<br />

the<br />

Certificate<br />

SSL<br />

ID<br />

cache.<br />

There<br />

is<br />

no<br />

absolute<br />

maximum<br />

size<br />

<strong>for</strong><br />

the<br />

cache.<br />

However,<br />

the<br />

size<br />

of<br />

the<br />

cache<br />

cannot<br />

exceed<br />

the<br />

size<br />

of<br />

the<br />

SSL<br />

ID<br />

cache.<br />

A<br />

maximum<br />

size<br />

of<br />

0<br />

allows<br />

an<br />

unlimited<br />

cache<br />

size.<br />

This<br />

stanza<br />

entry<br />

is<br />

required<br />

only<br />

when<br />

the<br />

accept-client-certs<br />

key<br />

is<br />

set<br />

to<br />

prompt_as_needed.<br />

The<br />

default<br />

value<br />

is<br />

1024.<br />

Example:<br />

cert-cache-max-entries<br />

=<br />

1024.<br />

See<br />

also<br />

“Enable<br />

and<br />

configure<br />

the<br />

Certificate<br />

SSL<br />

ID<br />

cache”<br />

on<br />

page<br />

153.<br />

cert-cache-timeout<br />

=<br />

number_of_seconds<br />

Maximum<br />

lifetime,<br />

in<br />

seconds,<br />

<strong>for</strong><br />

an<br />

entry<br />

in<br />

the<br />

Certificate<br />

SSL<br />

ID<br />

cache.<br />

The<br />

minimum<br />

value<br />

is<br />

zero.<br />

A<br />

value<br />

of<br />

zero<br />

mean<br />

that<br />

when<br />

the<br />

cache<br />

is<br />

full,<br />

the<br />

entries<br />

are<br />

cleared<br />

based<br />

on<br />

a<br />

Least<br />

Recently<br />

Used<br />

algorithm.<br />

This<br />

stanza<br />

entry<br />

is<br />

required<br />

only<br />

when<br />

the<br />

accept-client-certs<br />

key<br />

is<br />

set<br />

to<br />

prompt_as_needed.<br />

The<br />

default<br />

value<br />

is<br />

120.<br />

Example:<br />

cert-cache-timeout<br />

=<br />

120<br />

See<br />

also<br />

“Set<br />

the<br />

timeout<br />

<strong>for</strong><br />

Certificate<br />

SSL<br />

ID<br />

cache”<br />

on<br />

page<br />

154.<br />

[http-headers]<br />

stanza<br />

http-headers-auth<br />

=<br />

{none|http|https|both}<br />

416<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!