10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring<br />

authorization<br />

database<br />

updates<br />

and<br />

polling<br />

The<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

policy<br />

server<br />

(pdmgrd)<br />

manages<br />

the<br />

master<br />

authorization<br />

policy<br />

database<br />

and<br />

maintains<br />

location<br />

in<strong>for</strong>mation<br />

about<br />

other<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

servers<br />

in<br />

the<br />

secure<br />

domain.<br />

A<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

administrator<br />

can<br />

make<br />

security<br />

policy<br />

changes<br />

to<br />

the<br />

secure<br />

domain<br />

at<br />

any<br />

time.<br />

The<br />

policy<br />

server<br />

makes<br />

the<br />

necessary<br />

adjustments<br />

to<br />

the<br />

master<br />

authorization<br />

database<br />

whenever<br />

security<br />

policy<br />

changes<br />

are<br />

implemented.<br />

When<br />

the<br />

policy<br />

server<br />

makes<br />

a<br />

change<br />

to<br />

the<br />

master<br />

authorization<br />

database,<br />

it<br />

can<br />

send<br />

out<br />

notification<br />

of<br />

this<br />

change<br />

to<br />

all<br />

replica<br />

databases<br />

in<br />

the<br />

secure<br />

domain<br />

that<br />

support<br />

individual<br />

policy<br />

en<strong>for</strong>cers<br />

(such<br />

as<br />

<strong>WebSEAL</strong>).<br />

The<br />

policy<br />

en<strong>for</strong>cers<br />

must<br />

then<br />

request<br />

an<br />

actual<br />

database<br />

update<br />

from<br />

the<br />

master<br />

authorization<br />

database.<br />

<strong>WebSEAL</strong>,<br />

as<br />

a<br />

resource<br />

manager<br />

and<br />

policy<br />

en<strong>for</strong>cer,<br />

has<br />

three<br />

options<br />

to<br />

obtain<br />

in<strong>for</strong>mation<br />

about<br />

authorization<br />

database<br />

changes:<br />

v<br />

Listen<br />

<strong>for</strong><br />

update<br />

notifications<br />

from<br />

the<br />

policy<br />

server<br />

(configurable<br />

and<br />

enabled<br />

by<br />

default).<br />

v<br />

Check<br />

(poll)<br />

the<br />

master<br />

authorization<br />

database<br />

at<br />

regular<br />

intervals<br />

(configurable<br />

and<br />

disabled<br />

by<br />

default).<br />

v<br />

Enable<br />

both<br />

listening<br />

and<br />

polling.<br />

The<br />

[aznapi-configuration]<br />

stanza<br />

of<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

contains<br />

parameters<br />

<strong>for</strong><br />

configuring<br />

update<br />

notification<br />

listening<br />

and<br />

database<br />

polling.<br />

The<br />

path<br />

to<br />

<strong>WebSEAL</strong>’s<br />

local<br />

replica<br />

authorization<br />

policy<br />

database<br />

is<br />

defined<br />

by<br />

the<br />

db-file<br />

parameter:<br />

[aznapi-configuration]<br />

db-file<br />

=<br />

/var/pdweb/db/webseald.db<br />

Configuring<br />

update<br />

notification<br />

listening<br />

The<br />

listen-flags<br />

parameter,<br />

found<br />

in<br />

the<br />

[aznapi-configuration]<br />

stanza,<br />

enables<br />

and<br />

disables<br />

update<br />

notification<br />

listening<br />

by<br />

<strong>WebSEAL</strong>.<br />

By<br />

default,<br />

listening<br />

is<br />

disabled.<br />

To<br />

disable<br />

listening,<br />

enter<br />

″enable″.<br />

[aznapi-configuration]<br />

listen-flags<br />

=<br />

enable<br />

The<br />

ssl-listening-port<br />

parameter,<br />

found<br />

in<br />

the<br />

[ssl]<br />

stanza,<br />

configures<br />

the<br />

SSL<br />

port<br />

<strong>for</strong><br />

the<br />

listener:<br />

[ssl]<br />

ssl-listening-port<br />

=<br />

7234<br />

Configuring<br />

authorization<br />

database<br />

polling<br />

You<br />

can<br />

configure<br />

<strong>WebSEAL</strong><br />

to<br />

regularly<br />

poll<br />

the<br />

master<br />

authorization<br />

database<br />

<strong>for</strong><br />

update<br />

in<strong>for</strong>mation.<br />

The<br />

cache-refresh-interval<br />

parameter<br />

can<br />

be<br />

set<br />

to<br />

″default″,<br />

″disable″,<br />

or<br />

a<br />

specific<br />

time<br />

interval<br />

in<br />

seconds.<br />

The<br />

″default″<br />

setting<br />

is<br />

equal<br />

to<br />

600<br />

seconds.<br />

By<br />

default,<br />

polling<br />

is<br />

disabled.<br />

[aznapi-configuration]<br />

cache-refresh-interval<br />

=<br />

disable<br />

40<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!