10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Cryptographic<br />

hardware<br />

<strong>for</strong><br />

encryption<br />

and<br />

key<br />

storage<br />

<strong>WebSEAL</strong>,<br />

using<br />

GSKit<br />

<strong>for</strong><br />

SSL<br />

communication<br />

and<br />

key<br />

management,<br />

provides<br />

interface<br />

support<br />

<strong>for</strong><br />

cryptographic<br />

hardware.<br />

Cryptographic<br />

hardware<br />

can<br />

provide<br />

one<br />

or<br />

both<br />

of<br />

the<br />

following<br />

features:<br />

v<br />

Accelerated<br />

and<br />

secure<br />

SSL<br />

encryption<br />

and<br />

decryption<br />

tasks<br />

<strong>for</strong><br />

per<strong>for</strong>mance<br />

improvements<br />

during<br />

multiple<br />

online<br />

transactions<br />

v<br />

Accelerated<br />

and<br />

secure<br />

digital<br />

certificate<br />

key<br />

storage<br />

and<br />

management<br />

<strong>for</strong><br />

highly<br />

secure<br />

architecture<br />

during<br />

online<br />

transactions<br />

<strong>WebSEAL</strong><br />

and<br />

GSKit<br />

support<br />

the<br />

following<br />

interfaces<br />

to<br />

this<br />

cryptographic<br />

hardware:<br />

v<br />

BHAPI<br />

(RSA<br />

Security,<br />

Inc.’s<br />

API<br />

supporting<br />

its<br />

BSAFE<br />

product)<br />

v<br />

PKCS#11<br />

(Public<br />

Key<br />

Cryptographic<br />

Standard)<br />

Some<br />

cryptographic<br />

hardware<br />

supports<br />

both<br />

interfaces;<br />

some<br />

cryptographic<br />

hardware<br />

supports<br />

only<br />

one<br />

of<br />

the<br />

interfaces.<br />

In<br />

general,<br />

<strong>WebSEAL</strong><br />

(and<br />

GSKit)<br />

uses<br />

the<br />

BHAPI<br />

interface<br />

to<br />

support<br />

encryption<br />

and<br />

decryption.<br />

<strong>WebSEAL</strong><br />

(and<br />

GSKit)<br />

uses<br />

PKCS#11<br />

to<br />

support<br />

both<br />

encryption/decryption<br />

and<br />

key<br />

storage.<br />

<strong>WebSEAL</strong><br />

supports<br />

several<br />

hardware<br />

devices<br />

<strong>for</strong><br />

selected<br />

plat<strong>for</strong>ms.<br />

Consult<br />

the<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong><br />

Release<br />

Notes<br />

to<br />

obtain<br />

the<br />

latest<br />

in<strong>for</strong>mation<br />

on<br />

plat<strong>for</strong>m<br />

support<br />

<strong>for</strong><br />

these<br />

hardware<br />

cards.<br />

Cryptographic<br />

accelerator<br />

cards<br />

v<br />

nCipher<br />

nForce<br />

300<br />

v<br />

Rainbow<br />

CryptoSwift<br />

eCommerce<br />

Accelerator<br />

v<br />

<strong>IBM</strong><br />

4960<br />

Key<br />

Storage<br />

v<br />

nCipher<br />

nForce<br />

300<br />

v<br />

<strong>IBM</strong><br />

4758<br />

v<br />

Eracom<br />

Orange<br />

The<br />

following<br />

matrix<br />

illustrates<br />

the<br />

relationship<br />

between<br />

functionality<br />

and<br />

interface<br />

support<br />

<strong>for</strong><br />

each<br />

of<br />

these<br />

cards:<br />

BHAPI<br />

PKCS#11<br />

SSL<br />

Acceleration<br />

v<br />

Rainbow<br />

CryptoSwift<br />

v<br />

nCipher<br />

nForce<br />

300<br />

v<br />

<strong>IBM</strong><br />

4960<br />

v<br />

nCipher<br />

nForce<br />

300<br />

Key<br />

Storage<br />

v<br />

<strong>IBM</strong><br />

4758<br />

v<br />

nCipher<br />

nForce<br />

300<br />

v<br />

Eracom<br />

Orange<br />

The<br />

Rainbow<br />

CryptoSwift<br />

and<br />

nCipher<br />

nForce<br />

300<br />

(using<br />

BHAPI)<br />

are<br />

used<br />

<strong>for</strong><br />

public<br />

key<br />

operations<br />

(RSA<br />

key<br />

decryption).<br />

Keys<br />

are<br />

not<br />

stored<br />

on<br />

the<br />

accelerator<br />

device,<br />

but<br />

are<br />

stored<br />

in<br />

the<br />

pdsrv.kdb<br />

file.<br />

Accelerator<br />

devices<br />

are<br />

used<br />

to<br />

speed<br />

up<br />

the<br />

public<br />

key<br />

cryptographic<br />

functions<br />

of<br />

SSL.<br />

Hardware<br />

acceleration<br />

frees<br />

up<br />

the<br />

server<br />

processor,<br />

increases<br />

server<br />

throughput,<br />

and<br />

shortens<br />

wait<br />

time.<br />

The<br />

32<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!