10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Table<br />

4.<br />

P3P<br />

default<br />

header<br />

values<br />

(continued)<br />

CUR<br />

Cookie<br />

helps<br />

provide<br />

the<br />

current<br />

service.<br />

The<br />

current<br />

service<br />

is<br />

the<br />

access<br />

to<br />

the<br />

protected<br />

Web<br />

site.<br />

OTPi<br />

Cookie<br />

provides<br />

another<br />

service,<br />

to<br />

which<br />

the<br />

user<br />

has<br />

opted-in.<br />

OUR<br />

The<br />

Web<br />

site<br />

itself<br />

is<br />

the<br />

only<br />

recipient<br />

of<br />

the<br />

cookie<br />

and<br />

the<br />

in<strong>for</strong>mation<br />

linked<br />

to<br />

by<br />

the<br />

cookie<br />

NOR<br />

Neither<br />

the<br />

cookie<br />

data<br />

nor<br />

the<br />

data<br />

to<br />

which<br />

it<br />

links<br />

is<br />

retained<br />

after<br />

the<br />

user<br />

logs<br />

out<br />

or<br />

after<br />

the<br />

user<br />

session<br />

expires.<br />

UNI<br />

The<br />

cookie<br />

uses<br />

a<br />

unique<br />

identifier<br />

that<br />

represents<br />

the<br />

user,<br />

by<br />

using<br />

the<br />

session<br />

ID<br />

and<br />

the<br />

user<br />

name.<br />

P3P<br />

header<br />

configuration<br />

User<br />

that<br />

deploy<br />

<strong>WebSEAL</strong><br />

servers<br />

as<br />

part<br />

of<br />

the<br />

security<br />

solution<br />

<strong>for</strong><br />

their<br />

Web<br />

servers<br />

must<br />

specify<br />

the<br />

P3P<br />

compact<br />

policy<br />

<strong>for</strong><br />

their<br />

site.<br />

This<br />

step<br />

requires<br />

determining<br />

policy<br />

<strong>for</strong><br />

each<br />

of<br />

the<br />

privacy<br />

settings<br />

defined<br />

by<br />

the<br />

P3P<br />

specification.<br />

<strong>WebSEAL</strong><br />

provides<br />

a<br />

default<br />

policy<br />

that<br />

is<br />

accepted<br />

by<br />

the<br />

default<br />

settings<br />

<strong>for</strong><br />

the<br />

Microsoft<br />

Internet<br />

Explorer<br />

6<br />

browser.<br />

Web<br />

administrators<br />

should<br />

modify<br />

the<br />

default<br />

policy<br />

as<br />

needed<br />

to<br />

match<br />

the<br />

site<br />

policies<br />

<strong>for</strong><br />

handling<br />

of<br />

user<br />

data<br />

in<br />

cookies.<br />

Web<br />

administrators<br />

should<br />

test<br />

use<br />

of<br />

their<br />

policies<br />

with<br />

IE<br />

6<br />

to<br />

ensure<br />

that<br />

the<br />

<strong>WebSEAL</strong><br />

cookies<br />

continue<br />

to<br />

be<br />

accepted<br />

by<br />

IE<br />

6<br />

browsers.<br />

Web<br />

administrators<br />

should<br />

consult<br />

the<br />

P3P<br />

specification<br />

when<br />

defining<br />

their<br />

site<br />

policy.<br />

Multiple<br />

values<br />

are<br />

allowed<br />

<strong>for</strong><br />

each<br />

configuration<br />

entry,<br />

with<br />

the<br />

exception<br />

of<br />

the<br />

entries<br />

that<br />

require<br />

a<br />

value<br />

of<br />

yes<br />

or<br />

no.<br />

When<br />

a<br />

particular<br />

configuration<br />

entry<br />

is<br />

not<br />

declared,<br />

no<br />

indicators<br />

are<br />

added<br />

to<br />

the<br />

compact<br />

policy<br />

<strong>for</strong><br />

that<br />

entry.<br />

To<br />

configure<br />

the<br />

P3P<br />

compact<br />

policy<br />

<strong>for</strong><br />

use<br />

with<br />

<strong>WebSEAL</strong>,<br />

complete<br />

the<br />

following<br />

steps:<br />

1.<br />

Open<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

<strong>for</strong><br />

editing.<br />

Go<br />

to<br />

the<br />

[server]<br />

stanza.<br />

2.<br />

Decide<br />

if<br />

P3P<br />

headers<br />

from<br />

junctioned<br />

servers<br />

will<br />

be<br />

replaced<br />

or<br />

preserved.<br />

Set<br />

the<br />

following<br />

value:<br />

preserve-p3p-policy<br />

=<br />

{yes|no}<br />

The<br />

default<br />

value<br />

is<br />

no.<br />

Set<br />

this<br />

to<br />

yes<br />

if<br />

you<br />

want<br />

to<br />

preserve<br />

P3P<br />

headers.<br />

For<br />

more<br />

in<strong>for</strong>mation,<br />

see<br />

“Junction<br />

header<br />

preservation”<br />

on<br />

page<br />

60<br />

3.<br />

Go<br />

to<br />

the<br />

[p3p-header]<br />

stanza.<br />

Specify<br />

the<br />

access<br />

that<br />

the<br />

user<br />

will<br />

have<br />

to<br />

the<br />

in<strong>for</strong>mation<br />

in<br />

the<br />

cookie.<br />

Set<br />

the<br />

value<br />

<strong>for</strong><br />

the<br />

following<br />

entry:<br />

access<br />

=<br />

{none|all|nonident|contact-and-other|ident-contact|other-ident}<br />

The<br />

default<br />

setting<br />

is:<br />

access<br />

=<br />

none<br />

Table<br />

5.<br />

Supported<br />

values<br />

<strong>for</strong><br />

the<br />

access<br />

entry<br />

Value<br />

Description<br />

none<br />

No<br />

access<br />

to<br />

identified<br />

data<br />

is<br />

given.<br />

all<br />

<strong>Access</strong><br />

is<br />

given<br />

to<br />

all<br />

identified<br />

data<br />

nonident<br />

Web<br />

site<br />

does<br />

not<br />

collect<br />

identified<br />

data.<br />

62<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!