10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

SSL_RSA_EXPORT_WITH_RC4_40_MD5<br />

SSL_RSA_WITH_RC4_128_MD5<br />

SSL_RSA_WITH_RC4_128_SHA<br />

SSL_RSA_EXPORT_WITH_RC2_CBC_40_MD5<br />

SSL_RSA_EXPORT_WITH_DES40_CBC_SHA<br />

SSL_RSA_WITH_DES_CBC_SHA<br />

SSL_RSA_WITH_3DES_EDE_CBC_SHA<br />

TLS_RSA_WITH_AES_128_CBC_SHA<br />

TLS_RSA_WITH_AES_256_CBC_SHA<br />

TLS_RSA_EXPORT1024_WITH_DES_CBC_SHA<br />

TLS_RSA_EXPORT1024_WITH_RC4_56_SHA<br />

SSL_RSA_FIPS_WITH_3DES_EDE_CBC_SHA<br />

SSL_RSA_FIPS_WITH_3DES_EDE_CBC_SHA<br />

These<br />

TLS<br />

cipher<br />

specifications<br />

are<br />

also<br />

used<br />

with<br />

SSLV3.<br />

QOP<br />

<strong>for</strong><br />

individual<br />

hosts<br />

and<br />

networks<br />

The<br />

ssl-qop-mgmt<br />

=<br />

yes<br />

parameter<br />

also<br />

enables<br />

any<br />

settings<br />

that<br />

appear<br />

in<br />

the<br />

[ssl-qop-mgmt-hosts]<br />

and<br />

[ssl-qop-mgmt-networks]<br />

stanzas.<br />

These<br />

stanzas<br />

allow<br />

quality<br />

of<br />

protection<br />

management<br />

by<br />

specific<br />

host/network/netmask<br />

IP<br />

address.<br />

The<br />

[ssl-qop-mgmt-default]<br />

stanza<br />

lists<br />

the<br />

ciphers<br />

used<br />

<strong>for</strong><br />

all<br />

IP<br />

addresses<br />

not<br />

matched<br />

in<br />

the<br />

[ssl-qop-mgmt-hosts]<br />

and<br />

[ssl-qop-mgmt-networks]<br />

stanzas.<br />

Example<br />

configuration<br />

syntax<br />

<strong>for</strong><br />

hosts:<br />

[ssl-qop-mgmt-hosts]<br />

xxx.xxx.xxx.xxx<br />

=<br />

ALL<br />

yyy.yyy.yyy.yyy<br />

=<br />

RC2-128<br />

Example<br />

configuration<br />

syntax<br />

<strong>for</strong><br />

network/netmask:<br />

[ssl-qop-mgmt-networks]<br />

xxx.xxx.xxx.xxx/255.255.255.0<br />

=<br />

RC4-128<br />

yyy.yyy.yyy.yyy/255.255.0.0<br />

=<br />

DES-56<br />

The<br />

[ssl-qop-mgmt-hosts]<br />

and<br />

[ssl-qop-mgmt-networks]<br />

stanzas<br />

are<br />

provided<br />

<strong>for</strong><br />

backward<br />

compatibility<br />

only.<br />

It<br />

is<br />

recommended<br />

that<br />

you<br />

not<br />

use<br />

them<br />

<strong>for</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

configuration.<br />

Note<br />

that<br />

entry<br />

<strong>for</strong><br />

an<br />

IP<br />

address<br />

specified<br />

under<br />

[ssl-qop-mgmt-hosts]<br />

takes<br />

priority<br />

over<br />

an<br />

entry<br />

<strong>for</strong><br />

the<br />

same<br />

address<br />

in<br />

[ssl-qop-mgmt-networks].<br />

Likewise,<br />

an<br />

entry<br />

in<br />

[ssl-qop-mgmt-networks]<br />

takes<br />

priority<br />

over<br />

an<br />

entry<br />

<strong>for</strong><br />

the<br />

same<br />

address<br />

in<br />

[ssl-qop-mgmt-default].<br />

If<br />

you<br />

must<br />

use<br />

[ssl-qop-mgmt-hosts]<br />

or<br />

[ssl-qop-mgmt-networks]<br />

<strong>for</strong><br />

backwards<br />

compatibility,<br />

review<br />

the<br />

IP<br />

address<br />

settings<br />

under<br />

all<br />

stanzas<br />

to<br />

ensure<br />

that<br />

a<br />

specific<br />

IP<br />

address<br />

is<br />

not<br />

listed<br />

under<br />

more<br />

than<br />

one<br />

stanza.<br />

If<br />

an<br />

IP<br />

address<br />

is<br />

listed<br />

under<br />

more<br />

than<br />

one<br />

stanza,<br />

ensure<br />

that<br />

the<br />

order<br />

of<br />

evaluation<br />

yields<br />

the<br />

desired<br />

configuration.<br />

Chapter<br />

2.<br />

<strong>WebSEAL</strong><br />

server<br />

configuration<br />

39

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!