10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Integer<br />

value<br />

<strong>for</strong><br />

lifetime,<br />

in<br />

seconds,<br />

of<br />

inactive<br />

entries<br />

in<br />

the<br />

credential<br />

cache.<br />

The<br />

minimum<br />

number<br />

<strong>for</strong><br />

this<br />

value<br />

is<br />

0.<br />

A<br />

value<br />

of<br />

0<br />

means<br />

that<br />

when<br />

the<br />

cache<br />

is<br />

full,<br />

the<br />

entries<br />

are<br />

cleared<br />

based<br />

on<br />

a<br />

Least<br />

Recently<br />

Used<br />

algorithm.<br />

<strong>WebSEAL</strong><br />

does<br />

not<br />

impose<br />

a<br />

maximum<br />

value.<br />

See<br />

the<br />

guidelines<br />

on<br />

maximum<br />

size<br />

of<br />

integer<br />

values<br />

in<br />

“Guidelines<br />

<strong>for</strong><br />

configuring<br />

stanzas”<br />

on<br />

page<br />

378.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

Default<br />

value:<br />

600<br />

Example:<br />

inactive-timeout<br />

=<br />

600<br />

See<br />

also<br />

“Configuring<br />

the<br />

<strong>WebSEAL</strong><br />

session/credentials<br />

cache”<br />

on<br />

page<br />

133.<br />

ssl-id-sessions<br />

=<br />

{yes|no}<br />

Indicates<br />

whether<br />

to<br />

use<br />

the<br />

SSL<br />

ID<br />

to<br />

maintain<br />

a<br />

user’s<br />

HTTP<br />

login<br />

session.<br />

The<br />

Opera<br />

browser,<br />

in<br />

its<br />

default<br />

configuration,<br />

does<br />

not<br />

maintain<br />

SSL<br />

IDs<br />

across<br />

SSL<br />

connections.<br />

When<br />

using<br />

the<br />

Opera<br />

browser,<br />

ssl-id-sessions<br />

must<br />

be<br />

set<br />

to<br />

no.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

Default<br />

value:<br />

yes<br />

Example:<br />

ssl-id-sessions<br />

=<br />

yes<br />

See<br />

also<br />

“Maintaining<br />

state<br />

with<br />

session<br />

cookies”<br />

on<br />

page<br />

135.<br />

Usage<br />

note:<br />

This<br />

value<br />

must<br />

be<br />

set<br />

to<br />

no<br />

when<br />

the<br />

following<br />

key<br />

=<br />

value<br />

pair<br />

is<br />

set:<br />

[certificate]<br />

accept-client-certs<br />

=<br />

prompt_as_needed<br />

For<br />

more<br />

in<strong>for</strong>mation,<br />

see<br />

“Specify<br />

the<br />

certificate<br />

authentication<br />

mechanism”<br />

on<br />

page<br />

152.<br />

use-same-session<br />

=<br />

{yes|no}<br />

Indicates<br />

whether<br />

to<br />

use<br />

the<br />

same<br />

session<br />

<strong>for</strong><br />

SSL<br />

and<br />

HTTP<br />

clients.<br />

When<br />

set<br />

to<br />

yes,<br />

a<br />

user<br />

who<br />

has<br />

authenticated<br />

over<br />

HTTP<br />

will<br />

be<br />

authenticated<br />

when<br />

connecting<br />

over<br />

HTTPS.<br />

Likewise,<br />

the<br />

user<br />

who<br />

has<br />

authenticated<br />

over<br />

HTTPS<br />

will<br />

be<br />

authenticated<br />

when<br />

connecting<br />

over<br />

HTTP.<br />

Using<br />

yes<br />

will<br />

override<br />

ssl-id-sessions<br />

=<br />

yes,<br />

because<br />

HTTP<br />

clients<br />

do<br />

not<br />

read<br />

an<br />

SSL<br />

ID<br />

to<br />

maintain<br />

sessions.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

Default<br />

value:<br />

no<br />

Example:<br />

use-same-session<br />

=<br />

no<br />

See<br />

also<br />

“Maintaining<br />

state<br />

with<br />

session<br />

cookies”<br />

on<br />

page<br />

135<br />

resend-webseal-cookies<br />

=<br />

{yes|no}<br />

438<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!