10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Note:<br />

This<br />

step<br />

is<br />

specific<br />

to<br />

use<br />

of<br />

an<br />

LDAP<br />

user<br />

registry.<br />

This<br />

step<br />

is<br />

not<br />

required<br />

when<br />

using<br />

other<br />

registry<br />

types.<br />

If<br />

you<br />

want<br />

to<br />

use<br />

secure<br />

SSL<br />

communication<br />

between<br />

a<br />

<strong>WebSEAL</strong><br />

instance<br />

and<br />

the<br />

LDAP<br />

registry<br />

server,<br />

you<br />

must<br />

use<br />

the<br />

LDAP<br />

SSL<br />

key<br />

file<br />

<strong>for</strong><br />

this<br />

purpose.<br />

This<br />

is<br />

the<br />

key<br />

file<br />

that<br />

was<br />

created<br />

and<br />

distributed<br />

during<br />

installation<br />

of<br />

the<br />

LDAP<br />

client.<br />

If<br />

the<br />

initial<br />

<strong>WebSEAL</strong><br />

server<br />

is<br />

set<br />

up<br />

to<br />

use<br />

secure<br />

SSL<br />

communication<br />

with<br />

LDAP,<br />

multiple<br />

instances<br />

can<br />

use<br />

the<br />

same<br />

key<br />

file.<br />

When<br />

enabling<br />

SSL<br />

communication<br />

between<br />

<strong>WebSEAL</strong><br />

and<br />

the<br />

LDAP<br />

server,<br />

you<br />

must<br />

provide<br />

the<br />

following<br />

in<strong>for</strong>mation:<br />

–<br />

SSL<br />

key<br />

file<br />

name<br />

The<br />

file<br />

that<br />

contains<br />

the<br />

LDAP<br />

SSL<br />

certificate.<br />

–<br />

SSL<br />

key<br />

file<br />

password<br />

The<br />

password<br />

necessary<br />

to<br />

access<br />

the<br />

LDAP<br />

SSL<br />

key<br />

file<br />

–<br />

SSL<br />

Certificate<br />

label<br />

The<br />

LDAP<br />

client<br />

certificate<br />

label.<br />

This<br />

is<br />

optional.<br />

When<br />

the<br />

client<br />

label<br />

is<br />

not<br />

specified,<br />

the<br />

default<br />

certificate<br />

contained<br />

in<br />

the<br />

keyfile<br />

is<br />

used.<br />

Specify<br />

the<br />

client<br />

label<br />

when<br />

the<br />

keyfile<br />

contains<br />

more<br />

than<br />

one<br />

certificate,<br />

and<br />

the<br />

certificate<br />

to<br />

be<br />

used<br />

is<br />

not<br />

the<br />

default<br />

certificate.<br />

–<br />

SSL<br />

LDAP<br />

server<br />

port<br />

number<br />

The<br />

port<br />

number<br />

through<br />

which<br />

to<br />

communicate<br />

with<br />

the<br />

LDAP<br />

server.<br />

The<br />

default<br />

LDAP<br />

server<br />

port<br />

number<br />

is<br />

636.<br />

v<br />

Web<br />

document<br />

root<br />

directory<br />

The<br />

root<br />

directory<br />

of<br />

the<br />

hierarchy<br />

where<br />

the<br />

resources<br />

(protected<br />

objects)<br />

to<br />

be<br />

protected<br />

by<br />

<strong>WebSEAL</strong><br />

will<br />

be<br />

created.<br />

The<br />

name<br />

of<br />

the<br />

directory<br />

can<br />

be<br />

any<br />

valid<br />

directory<br />

name.<br />

The<br />

directory<br />

used<br />

by<br />

the<br />

default<br />

(first)<br />

<strong>WebSEAL</strong><br />

instance<br />

is:<br />

UNIX:<br />

installation_directory/pdweb/www-default/docs<br />

Windows:<br />

installation_directory\pdweb\www-default\docs<br />

Note<br />

that<br />

this<br />

directory<br />

could<br />

have<br />

been<br />

changed<br />

by<br />

the<br />

administrator<br />

during<br />

the<br />

configuration<br />

of<br />

the<br />

initial<br />

<strong>WebSEAL</strong><br />

server<br />

instance.<br />

When<br />

adding<br />

a<br />

new<br />

<strong>WebSEAL</strong><br />

server<br />

instance,<br />

a<br />

new<br />

Web<br />

document<br />

root<br />

directory<br />

is<br />

usually<br />

created<br />

<strong>for</strong><br />

the<br />

instance.<br />

During<br />

an<br />

interactive<br />

installation,<br />

a<br />

new<br />

directory<br />

is<br />

suggested,<br />

based<br />

on<br />

the<br />

following<br />

syntax:<br />

UNIX:<br />

installation_directory/pdweb/www-instance_name/docs<br />

Windows:<br />

installation_directory\pdweb\www-instance_name\docs<br />

The<br />

administrator<br />

can<br />

accept<br />

this<br />

name<br />

or<br />

specify<br />

an<br />

alternative.<br />

When<br />

adding<br />

a<br />

server<br />

instance<br />

by<br />

using<br />

the<br />

amwebcfg<br />

command<br />

line,<br />

or<br />

by<br />

using<br />

amwebcfg<br />

with<br />

a<br />

response<br />

file,<br />

the<br />

Web<br />

document<br />

root<br />

directory<br />

is<br />

created<br />

as<br />

follows:<br />

Chapter<br />

2.<br />

<strong>WebSEAL</strong><br />

server<br />

configuration<br />

19

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!