10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

HTTP_IV_USER<br />

298,<br />

336,<br />

338<br />

HTTP_PD_USER_SESSION_ID<br />

219<br />

HTTP_PD-USER-SESSION-ID<br />

345<br />

http-headers-auth<br />

156,<br />

416<br />

http-method-trace-enabled<br />

69,<br />

391<br />

http-method-trace-enabled-remote<br />

69,<br />

391<br />

http-port<br />

28,<br />

386<br />

http-request<br />

157,<br />

419<br />

HTTP-Tag-Value<br />

junction<br />

attribute<br />

218,<br />

344<br />

http-timeout<br />

456<br />

http-timeout<br />

(junctions)<br />

30<br />

HTTP/1.1<br />

responses<br />

308<br />

http.agent<br />

event<br />

pool<br />

100<br />

http.clf<br />

event<br />

pool<br />

100<br />

http.cof<br />

event<br />

pool<br />

(NCSA)<br />

100<br />

http.ref<br />

event<br />

pool<br />

100<br />

httpauthn<br />

157<br />

https<br />

29,<br />

386<br />

https-port<br />

29,<br />

386<br />

https-timeout<br />

456<br />

https-timeout<br />

(junctions)<br />

30<br />

I<br />

<strong>IBM</strong><br />

4758<br />

32<br />

<strong>IBM</strong><br />

4960<br />

32<br />

ICC<br />

33<br />

iKeyman<br />

230<br />

configuration<br />

<strong>for</strong><br />

cryptographic<br />

hardware<br />

34<br />

mutually<br />

authenticated<br />

SSL<br />

junctions<br />

282<br />

overview<br />

230<br />

SSL<br />

type<br />

junctions<br />

280<br />

<strong>WebSEAL</strong><br />

test<br />

certificate<br />

28<br />

ikmuser.properties<br />

34<br />

ikmuser.sample<br />

34<br />

illegal-url-substrings<br />

stanza<br />

56<br />

inactive-timeout<br />

134,<br />

437<br />

inherited<br />

ACL<br />

policy<br />

5<br />

instance<br />

name<br />

16<br />

interactive<br />

configuration<br />

21<br />

io-buffer-size<br />

457<br />

IP<br />

address<br />

authentication<br />

159<br />

ipaddr-auth<br />

159,<br />

417<br />

ipauth<br />

122<br />

is-master-authn-server<br />

269,<br />

431<br />

IV_JCT<br />

(junction<br />

cookie)<br />

292<br />

iv-creds<br />

298,<br />

338<br />

iv-groups<br />

298,<br />

338<br />

iv-remote-address<br />

299<br />

iv-user<br />

298,<br />

338<br />

J<br />

jmt<br />

load<br />

293<br />

jmt-map<br />

293,<br />

456<br />

jmt.conf<br />

293<br />

junction<br />

cookie,<br />

preventing<br />

naming<br />

conflicts<br />

286<br />

junction<br />

cookies<br />

292<br />

junction<br />

fairness<br />

42<br />

junction<br />

mapping<br />

table<br />

293<br />

junction<br />

stanza<br />

42<br />

junction-db<br />

276,<br />

456<br />

junctions<br />

-b<br />

filter<br />

318<br />

-b<br />

gso<br />

318<br />

-b<br />

ignore<br />

318<br />

junctions<br />

(continued)<br />

-b<br />

supply<br />

316<br />

authenticate<br />

with<br />

BA<br />

header<br />

(-B,<br />

-U,<br />

-W)<br />

283<br />

best<br />

practices<br />

339<br />

case-insensitive<br />

URLs<br />

(-i)<br />

300<br />

certificate<br />

authentication<br />

307<br />

client<br />

certificate<br />

(<strong>WebSEAL</strong>)<br />

(-K)<br />

283<br />

command<br />

reference<br />

491<br />

cookies<br />

across<br />

multiple<br />

-j<br />

junctions<br />

295<br />

Distinguished<br />

Name<br />

(DN)<br />

matching<br />

(-D)<br />

282<br />

en<strong>for</strong>cing<br />

permissions<br />

307<br />

filter<br />

absolute<br />

URLs<br />

with<br />

script<br />

filtering<br />

290<br />

filter<br />

URLs<br />

in<br />

responses<br />

288<br />

<strong>for</strong>cing<br />

new<br />

junction<br />

(-f)<br />

75,<br />

297<br />

<strong>for</strong>ms<br />

single<br />

sign-on<br />

(-S)<br />

332<br />

global<br />

sign-on<br />

(GSO)<br />

320<br />

gso<br />

options<br />

(-b<br />

gso,<br />

-T)<br />

322<br />

guidelines<br />

<strong>for</strong><br />

creating<br />

276<br />

HOST<br />

header<br />

best<br />

practices<br />

(-v)<br />

339<br />

host<br />

option<br />

(-h)<br />

280<br />

HTTP-Tag-Value<br />

attribute<br />

344<br />

HTTP/1.0<br />

and<br />

1.1<br />

responses<br />

308<br />

impact<br />

of<br />

-b<br />

options<br />

on<br />

mutually<br />

authenticated<br />

junctions<br />

284<br />

junction<br />

cookie,<br />

preventing<br />

naming<br />

conflicts<br />

286<br />

junction<br />

mapping<br />

table<br />

293<br />

LTPA<br />

(-A,<br />

-F,<br />

-Z)<br />

324<br />

modifying<br />

URLs<br />

from<br />

back-end<br />

applications<br />

287<br />

mount<br />

multiple<br />

servers<br />

307<br />

mutually<br />

authenticated<br />

(-D,<br />

-K,<br />

-B,<br />

-U,<br />

-W)<br />

282<br />

overview<br />

11,<br />

276<br />

pdadmin<br />

server<br />

task<br />

279<br />

preserving<br />

application<br />

cookie<br />

names<br />

296<br />

process<br />

server-relative<br />

URLs<br />

with<br />

cookies<br />

(-j)<br />

292<br />

process<br />

server-relative<br />

URLs<br />

with<br />

junction<br />

mapping<br />

293<br />

processing<br />

URLs<br />

in<br />

requests<br />

292<br />

proxy<br />

junctions<br />

(-H,<br />

-P)<br />

285<br />

query_contents<br />

309<br />

required<br />

options<br />

280<br />

scalability<br />

12<br />

session<br />

cookie<br />

to<br />

portal<br />

server<br />

(-k)<br />

300<br />

specify<br />

back-end<br />

UUID<br />

(-u)<br />

302<br />

stateful<br />

junction<br />

support<br />

(-s,<br />

-u)<br />

301<br />

supply<br />

client<br />

identity<br />

in<br />

HTTP<br />

headers<br />

(-c)<br />

298<br />

supply<br />

IP<br />

address<br />

in<br />

HTTP<br />

headers<br />

(-r)<br />

299<br />

supplying<br />

failure<br />

reason<br />

(-R)<br />

363<br />

type<br />

option<br />

(-t)<br />

280<br />

using<br />

WPM<br />

278<br />

virtual<br />

host<br />

name<br />

(-v)<br />

339<br />

<strong>WebSEAL</strong><br />

client<br />

certificate<br />

(-K)<br />

283<br />

<strong>WebSEAL</strong>-to-<strong>WebSEAL</strong><br />

(-C)<br />

286<br />

Windows<br />

file<br />

systems<br />

(-w)<br />

304<br />

worker<br />

thread<br />

allocation<br />

(-l)<br />

43<br />

worker<br />

thread<br />

allocation<br />

(-L)<br />

43<br />

K<br />

Kerberos<br />

authentication<br />

182,<br />

234<br />

kerberosv5<br />

242,<br />

420<br />

key<br />

database<br />

file<br />

types<br />

228<br />

key<br />

management<br />

configuring<br />

CRL<br />

checking<br />

231<br />

configuring<br />

the<br />

CRL<br />

cache<br />

231<br />

configuring<br />

<strong>WebSEAL</strong><br />

key<br />

database<br />

parameters<br />

229<br />

iKeyman<br />

utility<br />

230<br />

key<br />

database<br />

file<br />

types<br />

228<br />

managing<br />

client-side<br />

certificates<br />

228<br />

Index<br />

505

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!