10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

File<br />

names<br />

<strong>for</strong><br />

keys<br />

<strong>for</strong><br />

any<br />

domains<br />

that<br />

are<br />

participating<br />

in<br />

the<br />

e-community.<br />

This<br />

includes<br />

the<br />

domain<br />

in<br />

which<br />

the<br />

<strong>WebSEAL</strong><br />

server<br />

is<br />

running.<br />

These<br />

are<br />

shared<br />

on<br />

a<br />

pair-wise-by-domain<br />

basis.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

There<br />

is<br />

no<br />

default<br />

value.<br />

Example:<br />

ecssoserver.subnet.ibm.com<br />

=<br />

/tmp/ecsso.key<br />

[ecsso-token-attributes]<br />

stanza<br />

domain_name<br />

=<br />

pattern1<br />

[pattern2,]<br />

[patternN,<br />

....<br />

]<br />

Credential<br />

attributes<br />

to<br />

include<br />

in<br />

eCSSO<br />

authentication<br />

tokens.<br />

The<br />

domain_name<br />

specifies<br />

the<br />

destination<br />

domain<br />

containing<br />

the<br />

server<br />

that<br />

will<br />

consume<br />

the<br />

token.<br />

The<br />

value<br />

<strong>for</strong><br />

domain_name<br />

can<br />

be<br />

one<br />

or<br />

more<br />

entries.<br />

The<br />

value<br />

can<br />

be<br />

either<br />

a<br />

specific<br />

value<br />

or<br />

can<br />

be<br />

a<br />

pattern<br />

that<br />

uses<br />

standard<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

wildcard<br />

characters<br />

(<br />

*,<br />

[],<br />

^,<br />

\,<br />

?).<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

There<br />

is<br />

no<br />

default<br />

value<br />

Example:<br />

example1.com<br />

=<br />

my_cdas_attr_*<br />

<br />

=<br />

pattern1<br />

[pattern2,]<br />

[patternN,<br />

....<br />

]<br />

Credential<br />

attributes<br />

to<br />

include<br />

in<br />

eCSSO<br />

authentication<br />

tokens.<br />

When<br />

<strong>WebSEAL</strong><br />

cannot<br />

find<br />

a<br />

domain_name<br />

entry<br />

to<br />

match<br />

the<br />

domain,<br />

the<br />

entries<br />

in<br />

″″<br />

are<br />

used.<br />

The<br />

word<br />

<br />

is<br />

a<br />

key<br />

word<br />

and<br />

must<br />

not<br />

be<br />

modified.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

There<br />

is<br />

no<br />

default<br />

value<br />

Example:<br />

<br />

=<br />

my_cdas_attr_*<br />

[ecsso-incoming-attributes]<br />

stanza<br />

attribute_pattern<br />

=<br />

{preserve|refresh}<br />

Extended<br />

attributes<br />

to<br />

extract<br />

from<br />

incoming<br />

eCSSO<br />

authentication<br />

tokens.<br />

The<br />

attributes<br />

typically<br />

match<br />

those<br />

declared<br />

in<br />

the<br />

[cdsso-token-<br />

attributes]<br />

stanza<br />

<strong>for</strong><br />

the<br />

<strong>WebSEAL</strong><br />

server<br />

in<br />

the<br />

source<br />

domain.<br />

The<br />

attribute_pattern<br />

can<br />

be<br />

either<br />

a<br />

specific<br />

value<br />

or<br />

can<br />

be<br />

a<br />

pattern<br />

that<br />

uses<br />

standard<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

wildcard<br />

characters<br />

(<br />

*,<br />

[],<br />

^,<br />

\,<br />

?).<br />

The<br />

order<br />

of<br />

attribute_pattern<br />

entries<br />

is<br />

important.<br />

The<br />

first<br />

entry<br />

that<br />

matches<br />

the<br />

attribute<br />

is<br />

used.<br />

Other<br />

entries<br />

are<br />

ignored.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

There<br />

is<br />

no<br />

default<br />

value<br />

Example:<br />

my_cred_attr1<br />

=<br />

preserve<br />

434<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!