10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

The<br />

following<br />

table<br />

lists<br />

the<br />

supported<br />

values:<br />

Table<br />

13.<br />

Opt-in<br />

policy<br />

values<br />

Value<br />

Description<br />

opt-in<br />

Data<br />

may<br />

be<br />

used<br />

<strong>for</strong><br />

this<br />

purpose<br />

only<br />

when<br />

the<br />

user<br />

affirmatively<br />

requests<br />

this<br />

use.<br />

opt-out<br />

Data<br />

may<br />

be<br />

used<br />

<strong>for</strong><br />

this<br />

purpose<br />

unless<br />

the<br />

user<br />

requests<br />

that<br />

it<br />

not<br />

be<br />

used<br />

in<br />

this<br />

way.<br />

always<br />

Users<br />

cannot<br />

opt-in<br />

or<br />

opt-out<br />

of<br />

this<br />

use<br />

of<br />

their<br />

data.<br />

This<br />

is<br />

the<br />

default<br />

value.<br />

When<br />

the<br />

opt-in<br />

policy<br />

is<br />

not<br />

specified,<br />

the<br />

always<br />

policy<br />

applies.<br />

10.<br />

Specifies<br />

how<br />

long<br />

the<br />

in<strong>for</strong>mation<br />

in<br />

the<br />

cookie<br />

is<br />

retained.<br />

Set<br />

the<br />

value<br />

<strong>for</strong><br />

the<br />

following<br />

entry:<br />

retention<br />

=<br />

{no-retention|stated-purpose|legal-requirement|<strong>business</strong>-practices|<br />

indefinitely}<br />

The<br />

default<br />

setting<br />

is:<br />

retention<br />

=<br />

no-retention<br />

Table<br />

14.<br />

Supported<br />

values<br />

<strong>for</strong><br />

the<br />

retention<br />

entry<br />

Value<br />

Description<br />

no-retention<br />

In<strong>for</strong>mation<br />

is<br />

not<br />

retained<br />

<strong>for</strong><br />

more<br />

than<br />

a<br />

brief<br />

period<br />

of<br />

time<br />

necessary<br />

to<br />

make<br />

use<br />

of<br />

it<br />

during<br />

the<br />

course<br />

of<br />

a<br />

single<br />

online<br />

interaction.<br />

stated-purpose<br />

In<strong>for</strong>mation<br />

is<br />

retained<br />

to<br />

meet<br />

the<br />

stated<br />

purpose,<br />

and<br />

is<br />

to<br />

be<br />

discarded<br />

at<br />

the<br />

earliest<br />

time<br />

possible.<br />

legal-requirement<br />

In<strong>for</strong>mation<br />

is<br />

retained<br />

to<br />

meet<br />

a<br />

stated<br />

purpose,<br />

but<br />

the<br />

retention<br />

period<br />

is<br />

longer<br />

because<br />

of<br />

a<br />

legal<br />

requirement<br />

or<br />

liability.<br />

<strong>business</strong>-practices<br />

In<strong>for</strong>mation<br />

is<br />

retained<br />

under<br />

a<br />

service<br />

provider’s<br />

stated<br />

<strong>business</strong><br />

practices.<br />

indefinitely<br />

In<strong>for</strong>mation<br />

is<br />

retained<br />

<strong>for</strong><br />

an<br />

indeterminate<br />

period<br />

of<br />

time.<br />

11.<br />

Optionally,<br />

specify<br />

a<br />

reference<br />

to<br />

a<br />

full<br />

XML<br />

compact<br />

policy<br />

file.<br />

Specify<br />

a<br />

value<br />

<strong>for</strong><br />

the<br />

following<br />

entry:<br />

p3p-element<br />

=<br />

policyref=url_to_default_location_of_full_policy<br />

This<br />

entry<br />

is<br />

present<br />

but<br />

commented<br />

out,<br />

and<br />

there<strong>for</strong>e<br />

not<br />

active,<br />

in<br />

the<br />

default<br />

<strong>WebSEAL</strong><br />

configuration<br />

file.<br />

The<br />

default<br />

entry<br />

is<br />

the<br />

default<br />

location<br />

<strong>for</strong><br />

the<br />

full<br />

policy<br />

on<br />

any<br />

web<br />

site.<br />

#<br />

p3p-element<br />

=<br />

policyref=="/w3c/p3p.xml"<br />

When<br />

p3p-element<br />

is<br />

not<br />

set,<br />

browsers<br />

look<br />

by<br />

default<br />

<strong>for</strong><br />

the<br />

full<br />

policy<br />

in<br />

/w3c/p3p.xml.<br />

Note<br />

that<br />

some<br />

browsers<br />

might<br />

not<br />

refer<br />

to<br />

p3p-element<br />

but<br />

proceed<br />

directly<br />

to<br />

/w3c/p3p.xml.<br />

Note:<br />

Ensure<br />

that<br />

unauthenticated<br />

access<br />

is<br />

granted<br />

to<br />

/w3c/p3p.xml.<br />

See<br />

“Troubleshooting”<br />

on<br />

page<br />

68.<br />

Specifying<br />

a<br />

custom<br />

P3P<br />

compact<br />

policy<br />

As<br />

an<br />

alternative<br />

to<br />

setting<br />

values<br />

<strong>for</strong><br />

the<br />

entries<br />

in<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file,<br />

you<br />

can<br />

specify<br />

the<br />

exact<br />

contents<br />

of<br />

the<br />

P3P<br />

header.<br />

This<br />

can<br />

be<br />

useful,<br />

<strong>for</strong><br />

Chapter<br />

2.<br />

<strong>WebSEAL</strong><br />

server<br />

configuration<br />

67

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!