10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The<br />

maximum<br />

size<br />

of<br />

the<br />

in-memory<br />

policy<br />

cache<br />

is<br />

configurable.<br />

The<br />

cache<br />

consists<br />

of<br />

policy<br />

and<br />

the<br />

relationships<br />

between<br />

policy<br />

and<br />

resources.<br />

The<br />

knowledge<br />

that<br />

a<br />

resource<br />

has<br />

no<br />

directly<br />

associated<br />

policy<br />

is<br />

also<br />

cached.<br />

The<br />

maximum<br />

cache<br />

size<br />

should<br />

be<br />

relative<br />

to<br />

the<br />

number<br />

of<br />

policy<br />

objects<br />

defined<br />

and<br />

the<br />

number<br />

of<br />

resources<br />

protected<br />

and<br />

the<br />

available<br />

memory.<br />

A<br />

reasonable<br />

algorithm<br />

to<br />

begin<br />

with<br />

is:<br />

(number<br />

of<br />

policy<br />

objects<br />

*<br />

3)<br />

+<br />

(number<br />

of<br />

protected<br />

resources<br />

*<br />

3)<br />

This<br />

value<br />

controls<br />

how<br />

much<br />

in<strong>for</strong>mation<br />

is<br />

cached.<br />

A<br />

larger<br />

cache<br />

will<br />

potentially<br />

improve<br />

the<br />

application<br />

per<strong>for</strong>mance<br />

but<br />

use<br />

additional<br />

memory<br />

as<br />

well.<br />

Size<br />

is<br />

specified<br />

as<br />

the<br />

number<br />

of<br />

entries.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

Default<br />

value:<br />

none<br />

Example:<br />

policy-cache-size<br />

=<br />

32768<br />

azn-server-name<br />

=<br />

webseal_server_name<br />

Specifies<br />

the<br />

<strong>WebSEAL</strong><br />

server<br />

name<br />

<strong>for</strong><br />

use<br />

when<br />

contacting<br />

the<br />

policy<br />

server<br />

as<br />

an<br />

authorization<br />

API<br />

client.<br />

This<br />

stanza<br />

entry<br />

is<br />

set<br />

during<br />

<strong>WebSEAL</strong><br />

configuration<br />

and<br />

is<br />

typically<br />

not<br />

changed<br />

by<br />

the<br />

administrator.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

The<br />

default<br />

value<br />

consists<br />

of<br />

a<br />

combination<br />

of<br />

webseald<br />

with<br />

the<br />

hostname,<br />

separated<br />

by<br />

a<br />

hyphen<br />

(-):<br />

Example:<br />

azn-server-name<br />

=<br />

webseald-surf<br />

pd-user-name<br />

=<br />

webseal_server_identity<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

identity<br />

of<br />

the<br />

<strong>WebSEAL</strong><br />

server.<br />

This<br />

stanza<br />

entry<br />

is<br />

set<br />

by<br />

svrsslcfg<br />

during<br />

<strong>WebSEAL</strong><br />

configuration<br />

and<br />

should<br />

not<br />

be<br />

changed<br />

by<br />

the<br />

administrator.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

The<br />

default<br />

value<br />

consists<br />

of<br />

a<br />

combination<br />

of<br />

webseald<br />

with<br />

the<br />

hostname,<br />

separated<br />

by<br />

a<br />

<strong>for</strong>ward<br />

slash<br />

(/):<br />

Example:<br />

pd-user-name<br />

=<br />

webseald/surf<br />

pd-user-pwd<br />

=<br />

password<br />

Password<br />

<strong>for</strong><br />

the<br />

authorization<br />

API<br />

client<br />

identity.<br />

This<br />

identity<br />

represents<br />

the<br />

<strong>WebSEAL</strong><br />

server<br />

daemon.<br />

This<br />

stanza<br />

entry<br />

is<br />

set<br />

by<br />

svrsslcfg<br />

during<br />

<strong>WebSEAL</strong><br />

configuration<br />

and<br />

should<br />

not<br />

be<br />

changed<br />

by<br />

the<br />

administrator.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

There<br />

is<br />

no<br />

default<br />

value:<br />

Example:<br />

pd-user-pwd<br />

=<br />

ZsLuBKSo<br />

478<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!