10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The<br />

session<br />

cookie<br />

links<br />

to<br />

session<br />

data,<br />

and<br />

the<br />

failover<br />

cookie<br />

contains<br />

enough<br />

session<br />

in<strong>for</strong>mation<br />

to<br />

enable<br />

reconstruction<br />

of<br />

the<br />

session.<br />

The<br />

session<br />

cookie<br />

is<br />

intended<br />

only<br />

<strong>for</strong><br />

the<br />

origin<br />

server,<br />

is<br />

not<br />

retained<br />

past<br />

the<br />

end<br />

of<br />

the<br />

session,<br />

and<br />

assists<br />

in<br />

the<br />

process<br />

of<br />

session<br />

maintenance.<br />

The<br />

failover<br />

cookie<br />

is<br />

intended<br />

<strong>for</strong><br />

the<br />

failover<br />

(replicated)<br />

server,<br />

is<br />

not<br />

retained<br />

past<br />

the<br />

end<br />

of<br />

the<br />

session,<br />

and<br />

also<br />

assists<br />

in<br />

the<br />

process<br />

of<br />

session<br />

maintenance.<br />

Thus,<br />

session<br />

and<br />

failover<br />

cookies<br />

have<br />

the<br />

same<br />

P3P<br />

policy.<br />

This<br />

means<br />

that<br />

the<br />

combined<br />

worst<br />

case<br />

policy<br />

<strong>for</strong><br />

the<br />

cookies<br />

is<br />

the<br />

session<br />

cookie<br />

policy.<br />

Compact<br />

policy<br />

declaration<br />

The<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

provides<br />

a<br />

set<br />

of<br />

configuration<br />

options<br />

that<br />

match<br />

the<br />

compact<br />

policy<br />

XML<br />

syntax<br />

as<br />

specified<br />

in<br />

the<br />

World<br />

Wide<br />

Web<br />

Consortium<br />

Plat<strong>for</strong>m<br />

<strong>for</strong><br />

Privacy<br />

Preferences<br />

specification.<br />

The<br />

complete<br />

specification<br />

can<br />

be<br />

accessed<br />

at<br />

the<br />

following<br />

URL:<br />

http://www.w3.org/TR/P3P/<br />

<strong>WebSEAL</strong><br />

provides<br />

configuration<br />

file<br />

entries<br />

that<br />

map<br />

to<br />

the<br />

following<br />

XML<br />

elements<br />

in<br />

the<br />

compact<br />

policy:<br />

v<br />

access<br />

Indicates<br />

whether<br />

the<br />

site<br />

provides<br />

access<br />

to<br />

various<br />

kinds<br />

of<br />

in<strong>for</strong>mation.<br />

v<br />

categories<br />

The<br />

type<br />

of<br />

in<strong>for</strong>mation<br />

stored<br />

in<br />

the<br />

cookie<br />

v<br />

disputes<br />

Specifies<br />

whether<br />

the<br />

full<br />

P3P<br />

policy<br />

contains<br />

some<br />

in<strong>for</strong>mation<br />

regarding<br />

disputes<br />

over<br />

the<br />

in<strong>for</strong>mation<br />

contained<br />

within<br />

the<br />

cookie.<br />

v<br />

non-identifiable<br />

This<br />

element<br />

signifies<br />

that<br />

either<br />

no<br />

data<br />

is<br />

collected<br />

(including<br />

Web<br />

logs),<br />

or<br />

that<br />

the<br />

organization<br />

collecting<br />

the<br />

data<br />

will<br />

make<br />

the<br />

data<br />

anonymous.<br />

v<br />

purpose<br />

Purposes<br />

<strong>for</strong><br />

data<br />

processing<br />

relevant<br />

to<br />

the<br />

Web.<br />

v<br />

recipients<br />

The<br />

legal<br />

entity,<br />

or<br />

domain,<br />

beyond<br />

the<br />

service<br />

provider<br />

and<br />

its<br />

agents<br />

where<br />

data<br />

may<br />

be<br />

distributed.<br />

v<br />

remedies<br />

Remedies<br />

in<br />

case<br />

a<br />

policy<br />

breach<br />

occurs.<br />

v<br />

retention<br />

The<br />

type<br />

of<br />

retention<br />

policy<br />

in<br />

effect.<br />

v<br />

p3p-element<br />

This<br />

entry<br />

can<br />

be<br />

used<br />

to<br />

specify<br />

any<br />

elements<br />

to<br />

add<br />

to<br />

the<br />

P3P<br />

header<br />

in<br />

addition<br />

to<br />

the<br />

compact<br />

policy.<br />

This<br />

can<br />

be<br />

used<br />

to<br />

supply<br />

a<br />

reference<br />

to<br />

a<br />

full<br />

XML<br />

policy.<br />

The<br />

values<br />

<strong>for</strong><br />

purpose<br />

(except<br />

current)<br />

and<br />

recipients<br />

(except<br />

ours)<br />

have<br />

an<br />

additional<br />

option<br />

describing<br />

how<br />

the<br />

cookie<br />

data<br />

can<br />

be<br />

used.<br />

This<br />

defines<br />

whether<br />

the<br />

user<br />

is<br />

given<br />

a<br />

choice<br />

to<br />

opt-in<br />

or<br />

opt-out.<br />

Junction<br />

header<br />

preservation<br />

<strong>WebSEAL</strong><br />

enables<br />

you<br />

to<br />

specify<br />

whether<br />

P3P<br />

headers<br />

from<br />

junctioned<br />

applications<br />

are<br />

preserved<br />

or<br />

replaced.<br />

Note<br />

that<br />

this<br />

is<br />

not<br />

part<br />

of<br />

the<br />

P3P<br />

compact<br />

policy,<br />

but<br />

is<br />

a<br />

<strong>WebSEAL</strong><br />

function.<br />

60<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!