10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Step-up<br />

authentication<br />

levels.<br />

<strong>WebSEAL</strong><br />

enables<br />

authenticated<br />

users<br />

to<br />

increase<br />

the<br />

authentication<br />

level<br />

by<br />

use<br />

of<br />

step-up<br />

authentication.<br />

This<br />

key=value<br />

pair<br />

specifies<br />

which<br />

step-up<br />

authentication<br />

levels<br />

are<br />

supported<br />

by<br />

this<br />

<strong>WebSEAL</strong><br />

server.<br />

Do<br />

not<br />

specify<br />

an<br />

authentication<br />

level<br />

unless<br />

the<br />

authentication<br />

method<br />

is<br />

enabled.<br />

For<br />

example,<br />

you<br />

must<br />

enable<br />

either<br />

basic<br />

authentication<br />

or<br />

<strong>for</strong>ms<br />

authentication<br />

be<strong>for</strong>e<br />

setting<br />

level<br />

=<br />

password.<br />

Enter<br />

a<br />

separate<br />

key=value<br />

pair<br />

<strong>for</strong><br />

each<br />

supported<br />

level.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

Default<br />

values:<br />

level<br />

=<br />

authenticated<br />

level<br />

=<br />

password<br />

Example:<br />

level<br />

=<br />

password<br />

[step-up]<br />

stanza<br />

verify-step-up-user<br />

=<br />

{yes|no}<br />

En<strong>for</strong>ces<br />

policy<br />

requiring<br />

that<br />

the<br />

identity<br />

of<br />

the<br />

user<br />

per<strong>for</strong>ming<br />

the<br />

step-up<br />

operation<br />

match<br />

the<br />

identity<br />

of<br />

the<br />

user<br />

that<br />

per<strong>for</strong>med<br />

the<br />

original<br />

authentication<br />

operation.<br />

To<br />

en<strong>for</strong>ce<br />

this<br />

policy,<br />

set<br />

the<br />

value<br />

to<br />

yes.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

Default<br />

value:<br />

no<br />

Example:<br />

verify-step-up-user<br />

=<br />

yes<br />

[mpa]<br />

stanza<br />

mpa<br />

=<br />

{yes|no}<br />

Enables<br />

support<br />

<strong>for</strong><br />

multiplexing<br />

proxy<br />

agents.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

Default<br />

value:<br />

no<br />

Example:<br />

mpa<br />

=<br />

no<br />

418<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!