10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

e-community<br />

single<br />

sign-on<br />

v<br />

[e-community-sso]<br />

v<br />

[e-community-domain-keys]<br />

v<br />

[ecsso-token-attributes]<br />

v<br />

[ecsso-incoming-attributes]<br />

[e-community-sso]<br />

stanza<br />

e-community-sso-auth<br />

=<br />

{none|http|https|both}<br />

Enables<br />

participation<br />

in<br />

e-community<br />

single<br />

sign-on.<br />

Specifies<br />

which<br />

protocols<br />

are<br />

supported.<br />

The<br />

value<br />

both<br />

means<br />

both<br />

HTTP<br />

and<br />

HTTPS.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

Default<br />

value:<br />

none<br />

Example:<br />

e-community-sso-auth<br />

=<br />

none<br />

e-community-name<br />

=<br />

name<br />

String<br />

value<br />

that<br />

specifies<br />

an<br />

e-community<br />

name.<br />

When<br />

e-community<br />

single<br />

sign<br />

on<br />

is<br />

supported,<br />

this<br />

name<br />

must<br />

match<br />

any<br />

vouch-<strong>for</strong><br />

tokens<br />

or<br />

e-community<br />

cookies<br />

that<br />

are<br />

received.<br />

The<br />

string<br />

must<br />

not<br />

contain<br />

the<br />

equals<br />

sign<br />

(<br />

=<br />

)<br />

or<br />

ampersand<br />

(<br />

&<br />

).<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

There<br />

is<br />

no<br />

default<br />

value<br />

Example:<br />

e-community-name<br />

=<br />

company1<br />

is-master-authn-server<br />

=<br />

{yes|no}<br />

Specifies<br />

whether<br />

this<br />

<strong>WebSEAL</strong><br />

server<br />

accepts<br />

vouch-<strong>for</strong><br />

requests<br />

from<br />

other<br />

<strong>WebSEAL</strong><br />

instances.<br />

The<br />

<strong>WebSEAL</strong><br />

instances<br />

must<br />

have<br />

domain<br />

keys<br />

listed<br />

in<br />

the<br />

[e-community-domain-keys]<br />

stanza.<br />

When<br />

this<br />

value<br />

is<br />

yes,<br />

this<br />

<strong>WebSEAL</strong><br />

server<br />

is<br />

the<br />

master<br />

authentication<br />

server.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

There<br />

is<br />

no<br />

default<br />

value<br />

Example:<br />

is-master-authn-server<br />

=<br />

no<br />

master-authn-server<br />

=<br />

fully_qualified_hostname<br />

Location<br />

of<br />

the<br />

master<br />

authentication<br />

server.<br />

This<br />

value<br />

must<br />

be<br />

specified<br />

when<br />

is-master-authn-server<br />

is<br />

set<br />

to<br />

no.<br />

If<br />

a<br />

local<br />

domain<br />

login<br />

has<br />

not<br />

been<br />

per<strong>for</strong>med<br />

then<br />

authentication<br />

attempts<br />

are<br />

routed<br />

through<br />

the<br />

master<br />

machine.<br />

The<br />

master<br />

machine<br />

will<br />

vouch<br />

<strong>for</strong><br />

the<br />

user<br />

identity.<br />

The<br />

domain<br />

key<br />

<strong>for</strong><br />

the<br />

master-authn-server<br />

needs<br />

to<br />

be<br />

listed<br />

in<br />

the<br />

[e-community-domain-keys]<br />

stanza.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

There<br />

is<br />

no<br />

default<br />

value.<br />

Example:<br />

master-authn-server<br />

=<br />

diamond.dev.ibm.com<br />

master-http-port<br />

=<br />

port_number<br />

Appendix<br />

A.<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

reference<br />

431

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!