10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Positive<br />

integer<br />

value<br />

indicating<br />

the<br />

buffer<br />

size,<br />

in<br />

bytes,<br />

<strong>for</strong><br />

reading<br />

from<br />

and<br />

writing<br />

to<br />

a<br />

junction.<br />

The<br />

minimum<br />

value<br />

is<br />

1.<br />

<strong>WebSEAL</strong><br />

does<br />

not<br />

impose<br />

a<br />

maximum<br />

value.<br />

See<br />

the<br />

discussion<br />

of<br />

maximum<br />

values<br />

<strong>for</strong><br />

integers<br />

in<br />

“Guidelines<br />

<strong>for</strong><br />

configuring<br />

stanzas”<br />

on<br />

page<br />

378.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

Default<br />

value:<br />

4096<br />

Example:<br />

io-buffer-size<br />

=<br />

4096<br />

max-webseal-header-size<br />

=<br />

number_of_bytes<br />

Integer<br />

value<br />

indicating<br />

the<br />

maximum<br />

size,<br />

in<br />

bytes,<br />

of<br />

HTTP<br />

headers<br />

generated<br />

by<br />

the<br />

<strong>WebSEAL</strong><br />

server.<br />

Headers<br />

greater<br />

in<br />

size<br />

that<br />

this<br />

value<br />

are<br />

split<br />

across<br />

multiple<br />

HTTP<br />

Headers.<br />

A<br />

value<br />

of<br />

zero<br />

(0)<br />

disables<br />

this<br />

support.<br />

<strong>WebSEAL</strong><br />

imposes<br />

no<br />

maximum<br />

on<br />

this<br />

value.<br />

See<br />

the<br />

discussion<br />

on<br />

maximum<br />

values<br />

<strong>for</strong><br />

integer<br />

data<br />

types<br />

in<br />

“Guidelines<br />

<strong>for</strong><br />

configuring<br />

stanzas”<br />

on<br />

page<br />

378.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

Default<br />

value:<br />

0<br />

Example:<br />

max-webseal-header-size<br />

=<br />

0<br />

crl-ldap-server<br />

=<br />

server_name<br />

Name<br />

of<br />

the<br />

LDAP<br />

server<br />

to<br />

be<br />

referenced<br />

<strong>for</strong><br />

Certificate<br />

Revocation<br />

List<br />

(CRL)<br />

checking<br />

during<br />

authentication<br />

across<br />

SSL<br />

junctions.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

There<br />

is<br />

no<br />

default<br />

value.<br />

Example:<br />

crl-ldap-server<br />

=<br />

surf.santacruz.ibm.com<br />

crl-ldap-server-port<br />

=<br />

port_number<br />

Port<br />

number<br />

<strong>for</strong><br />

communication<br />

with<br />

the<br />

LDAP<br />

server<br />

specified<br />

in<br />

crl-ldap-server.<br />

The<br />

LDAP<br />

server<br />

is<br />

referenced<br />

<strong>for</strong><br />

Certificate<br />

Revocation<br />

List<br />

(CRL)<br />

checking<br />

during<br />

authentication<br />

across<br />

SSL<br />

junctions.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

When<br />

crl-ldap-server<br />

is<br />

set,<br />

this<br />

stanza<br />

entry<br />

is<br />

required.<br />

There<br />

is<br />

no<br />

default<br />

value.<br />

Example:<br />

crl-ldap-server-port<br />

=<br />

389<br />

crl-ldap-user<br />

=<br />

user_DN<br />

Fully<br />

qualified<br />

distinguished<br />

name<br />

(DN)<br />

of<br />

an<br />

LDAP<br />

user<br />

who<br />

has<br />

permissions<br />

to<br />

retrieve<br />

the<br />

Certificate<br />

Revocation<br />

List.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

A<br />

null<br />

value<br />

<strong>for</strong><br />

crl-ldap-user<br />

indicates<br />

that<br />

the<br />

SSL<br />

authenticator<br />

should<br />

bind<br />

to<br />

the<br />

LDAP<br />

server<br />

anonymously.<br />

There<br />

is<br />

no<br />

default<br />

value.<br />

crl-ldap-user-password<br />

=<br />

user_password<br />

458<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!