10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

List<br />

of<br />

string<br />

values<br />

to<br />

specify<br />

the<br />

allowed<br />

encryption<br />

levels<br />

<strong>for</strong><br />

HTTPS<br />

access<br />

<strong>for</strong><br />

a<br />

specific<br />

combination<br />

of<br />

IP<br />

address<br />

and<br />

netmask.<br />

The<br />

value<br />

ALL<br />

allows<br />

all<br />

ciphers.<br />

The<br />

value<br />

NONE<br />

disables<br />

all<br />

ciphers<br />

and<br />

uses<br />

an<br />

MD5<br />

MAC<br />

check<br />

sum.<br />

To<br />

specify<br />

allowable<br />

ciphers<br />

<strong>for</strong><br />

a<br />

selected<br />

group<br />

of<br />

IP<br />

addresses<br />

and<br />

netmasks,<br />

create<br />

a<br />

separate<br />

entry<br />

<strong>for</strong><br />

each<br />

address/netmask<br />

combination.<br />

For<br />

example:<br />

111.222.333.444/255.255.255.0<br />

=<br />

RC4-128<br />

222.666.333.111/255.255.0.0<br />

=<br />

RC2-128<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

There<br />

is<br />

no<br />

default<br />

value.<br />

Example:<br />

111.222.333.444/255.255.255.0<br />

=<br />

RC4-128<br />

Note<br />

that<br />

this<br />

stanza<br />

has<br />

been<br />

deprecated<br />

and<br />

is<br />

retained<br />

only<br />

<strong>for</strong><br />

backwards<br />

compatibility.<br />

For<br />

more<br />

in<strong>for</strong>mation,<br />

including<br />

a<br />

list<br />

of<br />

supported<br />

cipher_levels,<br />

see<br />

“Quality<br />

of<br />

protection<br />

levels”<br />

on<br />

page<br />

38.<br />

[ssl-qop-mgmt-default]<br />

stanza<br />

default<br />

=<br />

{ALL|NONE|cipher_level}<br />

List<br />

of<br />

string<br />

values<br />

to<br />

specify<br />

the<br />

allowed<br />

encryption<br />

levels<br />

<strong>for</strong><br />

HTTPS<br />

access.<br />

The<br />

value<br />

ALL<br />

allows<br />

all<br />

ciphers.<br />

The<br />

value<br />

NONE<br />

disables<br />

all<br />

ciphers<br />

and<br />

uses<br />

an<br />

MD5<br />

MAC<br />

check<br />

sum.<br />

To<br />

specify<br />

a<br />

selected<br />

group<br />

of<br />

ciphers,<br />

create<br />

a<br />

separate<br />

entry<br />

<strong>for</strong><br />

each<br />

cipher.<br />

For<br />

example:<br />

default<br />

=<br />

RC4-128<br />

default<br />

=<br />

RC2-128<br />

default<br />

=<br />

DES-168<br />

Values<br />

specified<br />

in<br />

this<br />

stanza<br />

entry<br />

are<br />

used<br />

<strong>for</strong><br />

all<br />

IP<br />

addresses<br />

that<br />

are<br />

not<br />

matched<br />

in<br />

either<br />

the<br />

[ssl-qop-mgmt-hosts]<br />

stanza<br />

entries<br />

or<br />

the<br />

[ssl-qop-mgmt-networks]<br />

stanza<br />

entries.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

Default<br />

value:<br />

ALL<br />

Example:<br />

default<br />

=<br />

ALL<br />

For<br />

more<br />

in<strong>for</strong>mation,<br />

including<br />

a<br />

list<br />

of<br />

supported<br />

cipher_levels,<br />

see<br />

“Quality<br />

of<br />

protection<br />

levels”<br />

on<br />

page<br />

38.<br />

436<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!