10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

–p<br />

port<br />

TCP<br />

port<br />

of<br />

the<br />

back-end<br />

third-party<br />

server.<br />

Default<br />

is<br />

80<br />

<strong>for</strong><br />

TCP<br />

junctions;<br />

443<br />

<strong>for</strong><br />

SSL<br />

junctions.<br />

–q<br />

location<br />

Relative<br />

path<br />

<strong>for</strong><br />

query_contents<br />

script.<br />

By<br />

default,<br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

looks<br />

<strong>for</strong><br />

query_contents<br />

in<br />

/cgi_bin/.<br />

If<br />

this<br />

directory<br />

is<br />

different<br />

or<br />

the<br />

query_contents<br />

file<br />

name<br />

is<br />

different,<br />

use<br />

this<br />

option<br />

to<br />

indicate<br />

to<br />

<strong>WebSEAL</strong><br />

the<br />

new<br />

URL<br />

to<br />

the<br />

file.<br />

Required<br />

<strong>for</strong><br />

back-end<br />

Windows<br />

servers.<br />

–r<br />

Insert<br />

incoming<br />

IP<br />

address<br />

in<br />

HTTP<br />

header<br />

across<br />

the<br />

junction.<br />

–R<br />

Allow<br />

denied<br />

requests<br />

and<br />

failure<br />

reason<br />

in<strong>for</strong>mation<br />

from<br />

authorization<br />

rules<br />

to<br />

proceed<br />

across<br />

the<br />

junction.<br />

–s<br />

Specifies<br />

that<br />

the<br />

junction<br />

should<br />

support<br />

stateful<br />

applications.<br />

By<br />

default,<br />

junctions<br />

are<br />

not<br />

stateful.<br />

–T<br />

resource/<br />

resource-group<br />

Name<br />

of<br />

GSO<br />

resource<br />

or<br />

resource<br />

group.<br />

Required<br />

<strong>for</strong><br />

and<br />

used<br />

only<br />

with<br />

–b<br />

gso<br />

option.<br />

–u<br />

UUID<br />

Specifies<br />

the<br />

UUID<br />

of<br />

a<br />

back-end<br />

server<br />

connected<br />

to<br />

<strong>WebSEAL</strong><br />

via<br />

a<br />

stateful<br />

junction<br />

(–s).<br />

–v<br />

virtual-host-name[:port]<br />

Virtual<br />

host<br />

name<br />

represented<br />

on<br />

the<br />

back-end<br />

server.<br />

This<br />

option<br />

supports<br />

a<br />

virtual<br />

host<br />

setup<br />

on<br />

the<br />

back-end<br />

server.<br />

You<br />

use<br />

–v<br />

when<br />

the<br />

back-end<br />

junction<br />

server<br />

expects<br />

a<br />

host<br />

name<br />

header<br />

because<br />

you<br />

are<br />

junctioning<br />

to<br />

one<br />

virtual<br />

instance<br />

of<br />

that<br />

server.<br />

The<br />

default<br />

HTTP<br />

header<br />

request<br />

from<br />

the<br />

browser<br />

does<br />

not<br />

know<br />

that<br />

the<br />

back-end<br />

server<br />

has<br />

multiple<br />

names<br />

and<br />

multiple<br />

virtual<br />

servers.<br />

You<br />

must<br />

configure<br />

<strong>WebSEAL</strong><br />

to<br />

supply<br />

that<br />

extra<br />

header<br />

in<strong>for</strong>mation<br />

in<br />

requests<br />

destined<br />

<strong>for</strong><br />

a<br />

back-end<br />

server<br />

set<br />

up<br />

as<br />

a<br />

virtual<br />

host.<br />

–w<br />

Win32<br />

filesystem<br />

support.<br />

Junction<br />

fairness<br />

–l<br />

percent-value<br />

Defines<br />

the<br />

soft<br />

limit<br />

<strong>for</strong><br />

consumption<br />

of<br />

worker<br />

threads.<br />

–L<br />

percent-value<br />

Defines<br />

the<br />

hard<br />

limit<br />

<strong>for</strong><br />

consumption<br />

of<br />

worker<br />

threads.<br />

LTPA<br />

junctions<br />

–A<br />

Enable<br />

and<br />

disable<br />

LTPA<br />

junctions.<br />

–F<br />

″keyfile″<br />

Location<br />

of<br />

key<br />

file<br />

used<br />

to<br />

encrypt<br />

LTPA<br />

cookie<br />

data.<br />

–Z<br />

″keyfile-password″<br />

Password<br />

<strong>for</strong><br />

the<br />

key<br />

file<br />

<strong>WebSEAL</strong>-to-<strong>WebSEAL</strong><br />

SSL<br />

junctions<br />

–C<br />

Mutual<br />

authentication<br />

between<br />

a<br />

front-end<br />

<strong>WebSEAL</strong><br />

server<br />

and<br />

a<br />

back-end<br />

<strong>WebSEAL</strong><br />

server<br />

over<br />

SSL.<br />

Requires<br />

–t<br />

ssl<br />

or<br />

–t<br />

sslproxy<br />

type.<br />

Forms<br />

single<br />

sign-on<br />

–S<br />

config-file<br />

Location<br />

of<br />

<strong>for</strong>ms<br />

single<br />

sign-on<br />

configuration<br />

file.<br />

Local<br />

junction<br />

options<br />

(use<br />

with<br />

–t<br />

local)<br />

–d<br />

dir<br />

Local<br />

directory<br />

to<br />

junction.<br />

**Required.**<br />

494<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!