10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Create<br />

a<br />

new<br />

junction<br />

<strong>for</strong><br />

an<br />

initial<br />

server<br />

Operation:<br />

Creates<br />

a<br />

new<br />

junction<br />

point<br />

and<br />

junctions<br />

an<br />

initial<br />

server.<br />

Syntax:<br />

create<br />

-t<br />

type<br />

-h<br />

host-name<br />

[options]<br />

junction-point<br />

Junction<br />

Type<br />

–t<br />

type<br />

**Required**<br />

Type<br />

of<br />

junction.<br />

One<br />

of:<br />

tcp,<br />

ssl,<br />

tcpproxy,<br />

sslproxy,<br />

local.<br />

Default<br />

port<br />

<strong>for</strong><br />

–t<br />

tcp<br />

is<br />

80.<br />

Default<br />

port<br />

<strong>for</strong><br />

–t<br />

ssl<br />

is<br />

443.<br />

Host<br />

Name<br />

–h<br />

host-name<br />

**Required**<br />

The<br />

DNS<br />

host<br />

name<br />

or<br />

IP<br />

address<br />

of<br />

the<br />

target<br />

back-end<br />

server.<br />

Options<br />

Mutual<br />

Authentication<br />

Over<br />

SSL<br />

–K<br />

″key-label″<br />

<strong>WebSEAL</strong><br />

uses<br />

client<br />

certificate<br />

to<br />

authenticate<br />

to<br />

back-end<br />

server.<br />

–B<br />

<strong>WebSEAL</strong><br />

uses<br />

BA<br />

header<br />

in<strong>for</strong>mation<br />

to<br />

authenticate<br />

to<br />

back-end<br />

server.<br />

Requires<br />

–U,<br />

and<br />

–W<br />

options.<br />

–U<br />

″username″<br />

<strong>WebSEAL</strong><br />

username.<br />

Use<br />

with<br />

–B<br />

to<br />

send<br />

BA<br />

header<br />

in<strong>for</strong>mation<br />

to<br />

back-end<br />

server.<br />

–W<br />

″password″<br />

<strong>WebSEAL</strong><br />

password.<br />

Use<br />

with<br />

–B<br />

to<br />

send<br />

BA<br />

header<br />

in<strong>for</strong>mation<br />

to<br />

back-end<br />

server.<br />

–D<br />

″DN″<br />

Specify<br />

Distinguished<br />

Name<br />

of<br />

back-end<br />

server<br />

certificate.<br />

This<br />

value,<br />

matched<br />

with<br />

actual<br />

certificate<br />

DN<br />

enhances<br />

authentication.<br />

Proxy<br />

junction<br />

options<br />

(requires<br />

–t<br />

tcpproxy<br />

or<br />

–t<br />

sslproxy)<br />

–H<br />

host-name<br />

The<br />

DNS<br />

host<br />

name<br />

or<br />

IP<br />

address<br />

of<br />

the<br />

proxy<br />

server.<br />

–P<br />

port<br />

The<br />

TCP<br />

port<br />

of<br />

the<br />

proxy<br />

server.<br />

Supplying<br />

BA<br />

header<br />

in<strong>for</strong>mation<br />

–b<br />

BA-value<br />

Defines<br />

how<br />

the<br />

<strong>WebSEAL</strong><br />

server<br />

passes<br />

HTTP<br />

BA<br />

authentication<br />

in<strong>for</strong>mation<br />

to<br />

the<br />

back-end<br />

server.<br />

One<br />

of:<br />

filter<br />

(default),<br />

ignore,<br />

supply,<br />

gso<br />

General<br />

TCP<br />

and<br />

SSL<br />

junction<br />

options<br />

–c<br />

id-types<br />

Insert<br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

client<br />

identity<br />

in<br />

HTTP<br />

headers<br />

across<br />

the<br />

junction.<br />

The<br />

id-types<br />

argument<br />

can<br />

include<br />

any<br />

combination<br />

of<br />

the<br />

following<br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

HTTP<br />

header<br />

types:<br />

iv-user,<br />

iv-user-l,<br />

iv-groups,<br />

iv-creds,<br />

all.<br />

–i<br />

<strong>WebSEAL</strong><br />

server<br />

treats<br />

URLs<br />

as<br />

case<br />

insensitive.<br />

–j<br />

Supply<br />

junction<br />

identification<br />

in<br />

a<br />

cookie<br />

to<br />

handle<br />

script<br />

generated<br />

server-relative<br />

URLs.<br />

–k<br />

Send<br />

session<br />

cookie<br />

to<br />

back-end<br />

portal<br />

server.<br />

Appendix<br />

B.<br />

<strong>WebSEAL</strong><br />

junction<br />

reference<br />

493

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!