10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

3.<br />

In<br />

the<br />

Open<br />

dialog<br />

window,<br />

select<br />

Cryptographic<br />

Tokens<br />

from<br />

the<br />

Key<br />

database<br />

type<br />

pull-down<br />

menu.<br />

4.<br />

If<br />

you<br />

have<br />

the<br />

cryptographic<br />

token<br />

specified<br />

in<br />

the<br />

ikmuser.properties<br />

file,<br />

you<br />

will<br />

see<br />

both<br />

the<br />

path<br />

and<br />

the<br />

library<br />

in<br />

the<br />

dialog<br />

box.<br />

If<br />

you<br />

do<br />

not<br />

see<br />

them,<br />

you<br />

can<br />

use<br />

the<br />

Browse...<br />

menu<br />

option.<br />

Click<br />

OK<br />

when<br />

this<br />

is<br />

done.<br />

5.<br />

Additionally,<br />

if<br />

you<br />

want<br />

to<br />

open<br />

an<br />

existing<br />

secondary<br />

key<br />

database<br />

(<strong>for</strong><br />

key<br />

data<br />

not<br />

stored<br />

on<br />

the<br />

cryptographic<br />

hardware—such<br />

as<br />

CA<br />

root<br />

certificates),<br />

check<br />

″Open<br />

Existing<br />

Key<br />

Database″.<br />

6.<br />

Browse<br />

<strong>for</strong><br />

and<br />

select<br />

the<br />

default<br />

<strong>WebSEAL</strong><br />

key<br />

database:<br />

UNIX:<br />

/opt/pdweb/www/certs/pdsrv.kdb<br />

Windows:<br />

C:\Program<br />

Files\<strong>Tivoli</strong>\pdweb\www\certs\pdsrv.kdb<br />

7.<br />

Click<br />

OK.<br />

The<br />

Token<br />

Password<br />

dialogue<br />

box<br />

appears.<br />

8.<br />

Enter<br />

the<br />

default<br />

password<br />

″pdsrv″.<br />

Click<br />

OK.<br />

9.<br />

The<br />

main<br />

iKeyman<br />

window<br />

returns.<br />

Request<br />

and<br />

store<br />

the<br />

<strong>WebSEAL</strong><br />

server<br />

certificate<br />

1.<br />

Follow<br />

instructions<br />

in<br />

the<br />

<strong>IBM</strong><br />

Global<br />

Security<br />

Kit<br />

Secure<br />

Sockets<br />

Layer<br />

and<br />

iKeyman<br />

User’s<br />

Guide<br />

to<br />

request<br />

a<br />

secure,<br />

signed<br />

digital<br />

certificate<br />

<strong>for</strong><br />

<strong>WebSEAL</strong><br />

from<br />

a<br />

Certificate<br />

Authority<br />

(CA).<br />

2.<br />

Follow<br />

instructions<br />

in<br />

the<br />

<strong>IBM</strong><br />

Global<br />

Security<br />

Kit<br />

Secure<br />

Sockets<br />

Layer<br />

and<br />

iKeyman<br />

User’s<br />

Guide<br />

to<br />

receive<br />

the<br />

<strong>WebSEAL</strong><br />

certificate<br />

from<br />

the<br />

CA<br />

and<br />

store<br />

it<br />

in<br />

a<br />

key<br />

database.<br />

When<br />

per<strong>for</strong>ming<br />

this<br />

procedure,<br />

select<br />

the<br />

token<br />

device<br />

representing<br />

the<br />

cryptographic<br />

hardware<br />

as<br />

the<br />

storage<br />

location<br />

<strong>for</strong><br />

the<br />

certificate.<br />

3.<br />

When<br />

it<br />

is<br />

stored<br />

on<br />

the<br />

token<br />

device,<br />

the<br />

key<br />

(certificate)<br />

appears<br />

(<strong>for</strong><br />

example)<br />

as:<br />

websealtoken:webseal<br />

The<br />

<strong>WebSEAL</strong><br />

key<br />

is<br />

stored<br />

on<br />

the<br />

cryptographic<br />

hardware<br />

and<br />

assigned<br />

to<br />

the<br />

token<br />

device<br />

labeled<br />

″websealtoken″.<br />

Configure<br />

<strong>WebSEAL</strong><br />

and<br />

GSKit<br />

to<br />

use<br />

the<br />

PKCS#11<br />

shared<br />

library<br />

Configure<br />

<strong>WebSEAL</strong><br />

to<br />

use<br />

the<br />

PKCS#11<br />

module<br />

(shared<br />

library).<br />

Edit<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

and<br />

add<br />

the<br />

appropriate<br />

line<br />

identifying<br />

the<br />

location<br />

of<br />

the<br />

shared<br />

library<br />

under<br />

the<br />

[ssl]<br />

stanza:<br />

UNIX<br />

nCipher<br />

nForce:<br />

[ssl]<br />

pkcs11-driver-path<br />

=<br />

/opt/nfast/toolkits/pkcs11/libcknfast.so<br />

<strong>IBM</strong><br />

4758-023<br />

and<br />

<strong>IBM</strong><br />

4960:<br />

[ssl]<br />

pkcs11-driver-path<br />

=<br />

/usr/lib/pkcs11/PKCS11_API.so<br />

Eracom<br />

Orange<br />

36<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!