10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Silent<br />

configuration<br />

overview<br />

You<br />

can<br />

use<br />

amwebcfg<br />

to<br />

configure<br />

a<br />

<strong>WebSEAL</strong><br />

server<br />

instance<br />

by<br />

reading<br />

all<br />

necessary<br />

values<br />

from<br />

a<br />

text<br />

file.<br />

The<br />

text<br />

file<br />

is<br />

called<br />

a<br />

response<br />

file.<br />

When<br />

amwebcfg<br />

obtains<br />

settings<br />

from<br />

the<br />

response<br />

file,<br />

it<br />

completes<br />

the<br />

configuration<br />

without<br />

further<br />

prompting<br />

of<br />

the<br />

administrator.<br />

The<br />

response<br />

file<br />

is<br />

not<br />

supplied<br />

by<br />

default.<br />

You<br />

must<br />

use<br />

a<br />

text<br />

editor<br />

to<br />

create<br />

it<br />

and<br />

enter<br />

the<br />

necessary<br />

values.<br />

The<br />

values<br />

consist<br />

of<br />

a<br />

series<br />

of<br />

key<br />

=<br />

value<br />

pairs.<br />

Each<br />

parameter<br />

entry<br />

is<br />

based<br />

on<br />

an<br />

option<br />

to<br />

amwebcfg.<br />

Each<br />

key<br />

=<br />

value<br />

pair<br />

is<br />

placed<br />

on<br />

a<br />

separate<br />

line.<br />

To<br />

insert<br />

a<br />

comment<br />

line<br />

,<br />

place<br />

a<br />

hash<br />

character<br />

(<br />

#<br />

)<br />

at<br />

the<br />

start<br />

of<br />

the<br />

line.<br />

The<br />

<strong>for</strong>mat<br />

of<br />

the<br />

response<br />

file<br />

is<br />

identical<br />

to<br />

the<br />

<strong>for</strong>mat<br />

of<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file.<br />

This<br />

installation<br />

option<br />

is<br />

useful<br />

when<br />

you<br />

have<br />

to<br />

create<br />

multiple<br />

<strong>WebSEAL</strong><br />

instances.<br />

After<br />

you<br />

have<br />

created<br />

and<br />

used<br />

one<br />

response<br />

file,<br />

you<br />

can<br />

use<br />

it<br />

as<br />

a<br />

template<br />

<strong>for</strong><br />

future<br />

response<br />

files.<br />

Copy<br />

the<br />

existing<br />

file<br />

to<br />

a<br />

new<br />

location,<br />

and<br />

edit<br />

it<br />

with<br />

values<br />

appropriate<br />

to<br />

the<br />

server<br />

instance.<br />

There<br />

are<br />

no<br />

restrictions<br />

on<br />

the<br />

location<br />

of<br />

the<br />

response<br />

file.<br />

Example<br />

command<br />

line<br />

amwebcfg<br />

-rspfile<br />

/tmp/response_file_name<br />

The<br />

following<br />

table<br />

shows<br />

an<br />

example<br />

response<br />

file<br />

<strong>for</strong><br />

the<br />

server<br />

instance<br />

values<br />

shown<br />

in<br />

“Example<br />

server<br />

instance<br />

configuration<br />

values”<br />

on<br />

page<br />

20.<br />

Example<br />

response<br />

file<br />

[webseal-config]<br />

action<br />

=<br />

config<br />

host<br />

=<br />

diamond.subnet2.ibm.com<br />

listener_port<br />

=<br />

7234<br />

admin_id<br />

=<br />

sec_master<br />

admin_pwd<br />

=<br />

mypassw0rd<br />

inst_name<br />

=<br />

web1<br />

nw_interface_yn<br />

=<br />

yes<br />

#<br />

If<br />

nw_interface_yn<br />

=<br />

no,<br />

do<br />

not<br />

need<br />

to<br />

specify<br />

the<br />

value<br />

<strong>for</strong><br />

ip_address<br />

ip_address<br />

=<br />

1.2.3.5<br />

#<br />

if<br />

SSL<br />

is<br />

not<br />

enabled,<br />

do<br />

not<br />

need<br />

to<br />

specify<br />

the<br />

values<br />

<strong>for</strong><br />

ssl_yn,<br />

#<br />

key_file,<br />

key_file_pwd,<br />

cert_label,<br />

and<br />

ssl_port<br />

ssl_yn<br />

=<br />

yes<br />

key_file<br />

=<br />

/tmp/client.kdb<br />

key_file_pwd<br />

=<br />

keyfilepassw0rd<br />

#<br />

cert_label<br />

is<br />

optional.<br />

#<br />

If<br />

you<br />

have<br />

no<br />

cert<br />

label,<br />

remove<br />

entry<br />

from<br />

response<br />

file<br />

cert_label<br />

=<br />

ibm_cert<br />

ssl_port<br />

=<br />

636<br />

http_yn<br />

=<br />

yes<br />

http_port<br />

=<br />

81<br />

https_yn<br />

=<br />

yes<br />

https_port<br />

=<br />

444<br />

#<br />

If<br />

the<br />

doc-root<br />

is<br />

not<br />

provided,<br />

amwebcfg<br />

creates<br />

the<br />

default<br />

one.<br />

#<br />

The<br />

default<br />

is<br />

/install_dir/pdweb/www-instance/docs<br />

#<br />

If<br />

you<br />

do<br />

not<br />

provide<br />

a<br />

value<br />

<strong>for</strong><br />

doc-root,<br />

remove<br />

the<br />

entry<br />

from<br />

the<br />

#<br />

response<br />

file<br />

or<br />

you<br />

will<br />

be<br />

prompted<br />

to<br />

enter<br />

it<br />

doc_root<br />

=<br />

/usr/www-web1/docs<br />

Chapter<br />

2.<br />

<strong>WebSEAL</strong><br />

server<br />

configuration<br />

23

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!