10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Quality<br />

of<br />

protection<br />

levels<br />

You<br />

can<br />

control<br />

the<br />

default<br />

level<br />

of<br />

encryption<br />

required<br />

<strong>for</strong><br />

access<br />

to<br />

<strong>WebSEAL</strong><br />

over<br />

SSL<br />

(HTTPS)<br />

by<br />

configuring<br />

the<br />

quality<br />

of<br />

protection<br />

(QOP).<br />

Default<br />

quality<br />

of<br />

protection<br />

management<br />

is<br />

controlled<br />

using<br />

parameters<br />

in<br />

the<br />

″SSL<br />

QUALITY<br />

OF<br />

PROTECTION<br />

MANAGEMENT″<br />

section<br />

of<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file:<br />

v<br />

Enable<br />

and<br />

disable<br />

QOP<br />

management<br />

with<br />

the<br />

ssl-qop-mgmt<br />

parameter<br />

v<br />

Specify<br />

allowed<br />

encryption<br />

levels<br />

in<br />

the<br />

[ssl-qop-mgmt-default]<br />

stanza<br />

1.<br />

Enable<br />

quality<br />

of<br />

protection<br />

management:<br />

[ssl-qop]<br />

ssl-qop-mgmt<br />

=<br />

yes<br />

2.<br />

Specify<br />

the<br />

default<br />

encryption<br />

level<br />

<strong>for</strong><br />

HTTPS<br />

access.<br />

The<br />

syntax<br />

is:<br />

default<br />

=<br />

{ALL|NONE|cipher_level}<br />

Supported<br />

values<br />

<strong>for</strong><br />

cipher_level<br />

are:<br />

NONE,<br />

ALL,<br />

NULL,<br />

DES-56,<br />

FIPS-DES-56,<br />

DES-168,<br />

FIPS-DES-168,<br />

RC2-40,<br />

RC2-128,<br />

RC4-40,<br />

RC4-56,<br />

RC4-128,<br />

AES-128,<br />

AES-256<br />

NONE<br />

disable<br />

For<br />

example:<br />

[ssl-qop-mgmt-default]<br />

default<br />

=<br />

ALL<br />

Note<br />

that<br />

you<br />

can<br />

also<br />

specify<br />

a<br />

selected<br />

group<br />

of<br />

ciphers:<br />

[ssl-qop-mgmt-default]<br />

default<br />

=<br />

RC4-128<br />

default<br />

=<br />

RC2-128<br />

default<br />

=<br />

DES-168<br />

Notes:<br />

v<br />

NONE<br />

means<br />

that<br />

no<br />

SSL<br />

connection<br />

allowed.<br />

v<br />

NULL<br />

means<br />

that<br />

unencrypted<br />

SSL<br />

connection<br />

allowed.<br />

v<br />

ALL<br />

means<br />

that<br />

all<br />

types<br />

of<br />

SSL<br />

connections<br />

allowed.<br />

v<br />

There<br />

can<br />

be<br />

multiple<br />

cipher/MAC<br />

made<br />

available<br />

to<br />

the<br />

connection<br />

<strong>for</strong><br />

a<br />

given<br />

qop<br />

cipher<br />

selection.<br />

These<br />

will<br />

still<br />

have<br />

the<br />

same<br />

encryption<br />

bit<br />

strength,<br />

just<br />

different<br />

MAC<br />

methods<br />

(SHA1<br />

or<br />

MD5)<br />

v<br />

RC2-128<br />

is<br />

only<br />

available<br />

with<br />

SSLv2.<br />

If<br />

it<br />

is<br />

the<br />

only<br />

cipher<br />

selection,<br />

<strong>WebSEAL</strong><br />

will<br />

disable<br />

SSLv3<br />

and<br />

TLSv1<br />

<strong>for</strong><br />

the<br />

affected<br />

connection.<br />

v<br />

NULL,<br />

FIPS-DES-56,<br />

FIPS-DES-168,<br />

RC4-56,<br />

AES-128,<br />

and<br />

AES-256<br />

are<br />

only<br />

available<br />

with<br />

SSLv3<br />

and<br />

TLSv1.<br />

If<br />

they<br />

are<br />

the<br />

only<br />

ciphers<br />

available<br />

to<br />

a<br />

given<br />

connection,<br />

SSLv2<br />

will<br />

be<br />

disabled<br />

<strong>for</strong><br />

the<br />

affected<br />

connection.<br />

v<br />

AES<br />

Support<br />

is<br />

determined<br />

automatically<br />

by<br />

GSKit<br />

based<br />

on<br />

the<br />

base-crypto-library<br />

setting.<br />

AES-128<br />

and<br />

AES-256<br />

are<br />

only<br />

available<br />

if<br />

AES<br />

Support<br />

is<br />

enabled<br />

by<br />

GSKit,<br />

else<br />

they<br />

will<br />

be<br />

ignored.<br />

v<br />

FIPS-DES-56<br />

and<br />

FIPS-DES-168<br />

are<br />

only<br />

available<br />

when<br />

fips-mode-<br />

processing<br />

is<br />

enabled<br />

(set<br />

to<br />

yes).<br />

Otherwise<br />

they<br />

are<br />

ignored<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

uses<br />

GSKit<br />

7.<br />

The<br />

Cipher<br />

specifications<br />

supported<br />

by<br />

GSKIT7<br />

when<br />

used<br />

in<br />

SSLv2/TLS<br />

in<br />

internet<br />

security<br />

are:<br />

SSL_RSA_WITH_NULL_MD5<br />

SSL_RSA_WITH_NULL_SHA<br />

38<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!