10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Integer<br />

value<br />

specifying<br />

the<br />

port<br />

number<br />

on<br />

which<br />

the<br />

master-authn-server<br />

listens<br />

<strong>for</strong><br />

HTTP<br />

request.<br />

The<br />

setting<br />

is<br />

necessary<br />

when<br />

e-community-sso-<br />

auth<br />

permits<br />

use<br />

of<br />

the<br />

HTTP<br />

protocol,<br />

and<br />

the<br />

master-authn-server<br />

listens<br />

<strong>for</strong><br />

HTTP<br />

requests<br />

on<br />

a<br />

port<br />

other<br />

than<br />

the<br />

standard<br />

HTTP<br />

port<br />

(port<br />

80).<br />

This<br />

stanza<br />

entry<br />

is<br />

ignored<br />

if<br />

this<br />

<strong>WebSEAL</strong><br />

server<br />

is<br />

the<br />

master<br />

authentication<br />

server.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

There<br />

is<br />

no<br />

default<br />

value.<br />

Example:<br />

master-http-port<br />

=<br />

81<br />

master-https-port<br />

=<br />

port_number<br />

Integer<br />

value<br />

specifying<br />

the<br />

port<br />

number<br />

on<br />

which<br />

the<br />

master-authn-server<br />

listens<br />

<strong>for</strong><br />

HTTPS<br />

requests.<br />

The<br />

setting<br />

is<br />

necessary<br />

when<br />

e-community-sso-auth<br />

permits<br />

use<br />

of<br />

the<br />

HTTPS<br />

protocol,<br />

and<br />

the<br />

master-authn-server<br />

listens<br />

<strong>for</strong><br />

HTTPS<br />

requests<br />

on<br />

a<br />

port<br />

other<br />

than<br />

the<br />

standard<br />

HTTPS<br />

port<br />

(port<br />

443).<br />

This<br />

stanza<br />

entry<br />

is<br />

ignored<br />

if<br />

this<br />

<strong>WebSEAL</strong><br />

server<br />

is<br />

the<br />

master<br />

authentication<br />

server.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

There<br />

is<br />

no<br />

default<br />

value.<br />

Example:<br />

master-https-port<br />

=<br />

444<br />

vf-token-lifetime<br />

=<br />

number_of_seconds<br />

Positive<br />

integer<br />

indicating<br />

the<br />

lifetime,<br />

in<br />

seconds,<br />

of<br />

the<br />

vouch-<strong>for</strong><br />

token.<br />

This<br />

is<br />

set<br />

to<br />

account<br />

<strong>for</strong><br />

clock<br />

skew<br />

between<br />

participant<br />

servers.<br />

The<br />

minimum<br />

value<br />

is<br />

1<br />

second.<br />

There<br />

is<br />

no<br />

maximum<br />

value.<br />

See<br />

the<br />

discussion<br />

of<br />

integer<br />

maximum<br />

values<br />

in<br />

“Guidelines<br />

<strong>for</strong><br />

configuring<br />

stanzas”<br />

on<br />

page<br />

378.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

Default<br />

value:<br />

180<br />

Example:<br />

vf-token-lifetime<br />

=<br />

180<br />

vf-url<br />

=<br />

URL_designation<br />

Designator<br />

<strong>for</strong><br />

vouch-<strong>for</strong><br />

URL.<br />

This<br />

specifies<br />

the<br />

start<br />

of<br />

a<br />

URL<br />

relative<br />

to<br />

the<br />

server<br />

root.<br />

This<br />

is<br />

used<br />

to<br />

construct<br />

vouch-<strong>for</strong><br />

requests<br />

<strong>for</strong><br />

participating<br />

e-community<br />

single<br />

sign-on<br />

servers,<br />

and<br />

to<br />

distinguish<br />

requests<br />

<strong>for</strong><br />

vouch-<strong>for</strong><br />

in<strong>for</strong>mation<br />

from<br />

other<br />

requests<br />

by<br />

the<br />

master<br />

authentication<br />

server.<br />

The<br />

URL_designation<br />

string<br />

can<br />

contain<br />

alphanumerics<br />

and<br />

the<br />

following<br />

special<br />

characters:<br />

dollar<br />

sign<br />

(<br />

$<br />

),<br />

hyphen<br />

(<br />

-<br />

),<br />

underscore<br />

(<br />

_<br />

),<br />

period<br />

(<br />

.<br />

),<br />

plus<br />

sign<br />

(<br />

+<br />

),<br />

exclamation<br />

point<br />

(<br />

!<br />

),<br />

asterisk<br />

(<br />

*<br />

),<br />

single<br />

quote<br />

(<br />

’<br />

),<br />

parentheses<br />

″<br />

(<br />

)<br />

″<br />

and<br />

comma<br />

(<br />

,<br />

).<br />

Questions<br />

marks<br />

(<br />

?<br />

)<br />

are<br />

not<br />

allowed<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

When<br />

the<br />

stanza<br />

entry<br />

is<br />

not<br />

present<br />

in<br />

the<br />

configuration<br />

file,<br />

the<br />

default<br />

value<br />

is<br />

/pkmsvouch<strong>for</strong>.<br />

Example:<br />

vf-url<br />

=<br />

/pkmsvouch<strong>for</strong><br />

vf-argument<br />

=<br />

vouch-<strong>for</strong>_token_name<br />

432<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!