10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

String<br />

value<br />

containing<br />

the<br />

name<br />

of<br />

the<br />

vouch-<strong>for</strong><br />

token<br />

contained<br />

in<br />

a<br />

vouch-<strong>for</strong><br />

reply.<br />

This<br />

is<br />

used<br />

to<br />

construct<br />

the<br />

vouch-<strong>for</strong><br />

replies<br />

by<br />

the<br />

master<br />

authentication<br />

server,<br />

and<br />

to<br />

distinguish<br />

incoming<br />

requests<br />

as<br />

ones<br />

with<br />

vouch-<strong>for</strong><br />

in<strong>for</strong>mation<br />

by<br />

participating<br />

e-community<br />

single<br />

sign-on<br />

servers.<br />

Valid<br />

characters<br />

<strong>for</strong><br />

the<br />

string<br />

are<br />

ASCII<br />

characters<br />

except<br />

<strong>for</strong><br />

ampersand<br />

(<br />

&<br />

),<br />

equals<br />

sign<br />

(<br />

=<br />

),<br />

and<br />

question<br />

mark<br />

(<br />

?<br />

).<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

Default<br />

value:<br />

PD-VF<br />

Example:<br />

vf-argument<br />

=<br />

PD-VF<br />

ec-cookie-lifetime<br />

=<br />

number_of_minutes<br />

Positive<br />

integer<br />

value<br />

indicating<br />

the<br />

lifetime<br />

of<br />

an<br />

e-community<br />

cookie.<br />

Minimum<br />

value<br />

is<br />

1.<br />

There<br />

is<br />

no<br />

maximum<br />

value.<br />

See<br />

the<br />

discussion<br />

of<br />

integer<br />

maximum<br />

values<br />

in<br />

“Guidelines<br />

<strong>for</strong><br />

configuring<br />

stanzas”<br />

on<br />

page<br />

378.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

Default:<br />

300<br />

Example:<br />

ec-cookie-lifetime<br />

=<br />

300<br />

ecsso-allow-unauth<br />

=<br />

{yes|no}<br />

Enables<br />

or<br />

disables<br />

unauthenticated<br />

access<br />

to<br />

unprotected<br />

resources<br />

on<br />

an<br />

e-community<br />

SSO<br />

slave<br />

server.<br />

The<br />

value<br />

yes<br />

enables<br />

unauthenticated<br />

access.<br />

The<br />

value<br />

no<br />

disables<br />

access.<br />

For<br />

compatibility<br />

with<br />

versions<br />

of<br />

<strong>WebSEAL</strong><br />

prior<br />

to<br />

5.1<br />

set<br />

this<br />

to<br />

no.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

Default:<br />

yes<br />

Example:<br />

ecsso-allow-unauth<br />

=<br />

yes<br />

use-utf8<br />

=<br />

{yes|no}<br />

Use<br />

UTF–8<br />

encoding<br />

<strong>for</strong><br />

tokens<br />

used<br />

in<br />

e-community<br />

single<br />

sign-on.<br />

Beginning<br />

with<br />

Version<br />

5.1,<br />

<strong>WebSEAL</strong><br />

servers<br />

use<br />

UTF-8<br />

encoding<br />

by<br />

default.<br />

When<br />

this<br />

stanza<br />

entry<br />

is<br />

set<br />

to<br />

true,<br />

tokens<br />

can<br />

be<br />

exchanged<br />

with<br />

other<br />

<strong>WebSEAL</strong><br />

servers<br />

that<br />

use<br />

UTF-8<br />

encoding.<br />

This<br />

enables<br />

tokens<br />

to<br />

used<br />

across<br />

different<br />

code<br />

pages<br />

(such<br />

as<br />

<strong>for</strong><br />

a<br />

different<br />

language).<br />

For<br />

backwards<br />

compatibility<br />

with<br />

tokens<br />

created<br />

by<br />

<strong>WebSEAL</strong><br />

servers<br />

from<br />

version<br />

prior<br />

to<br />

5.1,<br />

set<br />

this<br />

stanza<br />

entry<br />

to<br />

no.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

Default:<br />

yes<br />

Example:<br />

use-utf8<br />

=<br />

yes<br />

See<br />

also<br />

“Multi-locale<br />

support<br />

with<br />

UTF-8”<br />

on<br />

page<br />

44.<br />

[e-community-domain-keys]<br />

stanza<br />

domain_name<br />

=<br />

fully_quailified_path<br />

Appendix<br />

A.<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

reference<br />

433

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!