10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

[ssl]<br />

pkcs11-driver-path<br />

=<br />

/opt/Eracom/lib/libcryptoki.so<br />

Windows<br />

nCipher<br />

nForce:<br />

[ssl]<br />

pkcs11-driver-path<br />

=<br />

C:\nfast\toolkits\pkcs11\cknfast.dll<br />

<strong>IBM</strong><br />

4758-023:<br />

[ssl]<br />

pkcs11-driver-path<br />

=<br />

C:\Program<br />

Files\ibm\PKCS11\bin\nt\cryptoki.dll<br />

Eracom<br />

Orange<br />

[ssl]<br />

pkcs11-driver-path<br />

=<br />

C:\Program<br />

Files\Eracom\ProtectedToolKit<br />

C<br />

Runtime\cryptoki.dll<br />

In<br />

addition,<br />

specify<br />

the<br />

names<br />

of<br />

the<br />

token<br />

label<br />

and<br />

password<br />

under<br />

the<br />

same<br />

[ssl]<br />

stanza:<br />

For<br />

this<br />

example:<br />

[ssl]<br />

pkcs11-token-label<br />

=<br />

websealtoken<br />

pkcs11-token-pwd<br />

=<br />

secret<br />

Modify<br />

the<br />

<strong>WebSEAL</strong><br />

server<br />

certificate<br />

label<br />

Configure<br />

<strong>WebSEAL</strong><br />

to<br />

use<br />

this<br />

new<br />

hardware-based<br />

key<br />

rather<br />

than<br />

the<br />

default<br />

key<br />

in<br />

its<br />

communications<br />

with<br />

browser<br />

clients.<br />

Modify<br />

the<br />

webseal-cert-keyfile-<br />

label<br />

parameter<br />

in<br />

the<br />

[ssl]<br />

stanza<br />

of<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

to<br />

designate<br />

the<br />

new<br />

key<br />

label.<br />

[ssl]<br />

webseal-cert-keyfile-label<br />

=<br />

:<br />

For<br />

this<br />

example:<br />

[ssl]<br />

webseal-cert-keyfile-label<br />

=<br />

websealtoken:webseal<br />

Disable<br />

acceleration<br />

mode<br />

<strong>for</strong><br />

nCipher<br />

nForce<br />

300<br />

If<br />

you<br />

want<br />

to<br />

use<br />

the<br />

nCipher<br />

nForce<br />

300<br />

device<br />

only<br />

<strong>for</strong><br />

key<br />

storage,<br />

and<br />

not<br />

SSL<br />

acceleration,<br />

you<br />

can<br />

configure<br />

<strong>WebSEAL</strong><br />

to<br />

disable<br />

the<br />

automatic<br />

use<br />

of<br />

this<br />

device<br />

<strong>for</strong><br />

BHAPI<br />

acceleration.<br />

The<br />

disable-ncipher-bsafe<br />

parameter<br />

is<br />

available<br />

in<br />

the<br />

[ssl]<br />

stanza<br />

of<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file.<br />

To<br />

disable<br />

automatic<br />

SSL<br />

acceleration<br />

over<br />

the<br />

BHAPI<br />

interface,<br />

set<br />

this<br />

parameter<br />

to<br />

″yes″.<br />

For<br />

example:<br />

[ssl]<br />

disable-ncipher-bsafe<br />

=<br />

yes<br />

By<br />

default,<br />

this<br />

parameter<br />

is<br />

set<br />

to<br />

″no″<br />

(that<br />

is,<br />

<strong>WebSEAL</strong><br />

automatically<br />

uses<br />

the<br />

hardware<br />

<strong>for</strong><br />

SSL<br />

acceleration<br />

over<br />

the<br />

BHAPI<br />

interface).<br />

Restart<br />

<strong>WebSEAL</strong><br />

You<br />

must<br />

restart<br />

<strong>WebSEAL</strong><br />

<strong>for</strong><br />

all<br />

cryptographic<br />

hardware<br />

configuration<br />

to<br />

take<br />

effect.<br />

You<br />

can<br />

verify<br />

that<br />

<strong>WebSEAL</strong><br />

is<br />

using<br />

the<br />

cryptographic<br />

hardware<br />

by<br />

examining<br />

entries<br />

contained<br />

in<br />

the<br />

msg_webseald.log<br />

file.<br />

Chapter<br />

2.<br />

<strong>WebSEAL</strong><br />

server<br />

configuration<br />

37

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!