10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

example,<br />

when<br />

your<br />

compact<br />

policy<br />

string<br />

has<br />

been<br />

generated<br />

by<br />

another<br />

utility,<br />

and<br />

you<br />

want<br />

to<br />

use<br />

that<br />

string<br />

<strong>for</strong><br />

the<br />

P3P<br />

policy.<br />

To<br />

specify<br />

a<br />

custom<br />

P3P<br />

compact<br />

policy,<br />

complete<br />

the<br />

following<br />

steps:<br />

1.<br />

Remove<br />

the<br />

default<br />

values<br />

from<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file.<br />

For<br />

example,<br />

change<br />

the<br />

default<br />

<strong>WebSEAL</strong><br />

entries<br />

to<br />

the<br />

following:<br />

[p3p-header]<br />

access<br />

=<br />

purpose<br />

=<br />

purpose<br />

=<br />

recipients<br />

=<br />

retention<br />

=<br />

categories<br />

=<br />

2.<br />

Add<br />

your<br />

custom<br />

compact<br />

policy<br />

string<br />

to<br />

the<br />

p3p-element<br />

entry:<br />

p3p-element<br />

=<br />

CP="your_series_of_compact_policy_abbreviations"<br />

Any<br />

number<br />

of<br />

values<br />

can<br />

be<br />

added.<br />

The<br />

order<br />

of<br />

the<br />

values<br />

is<br />

not<br />

significant.<br />

Troubleshooting<br />

v<br />

Problem:<br />

Browser<br />

cannot<br />

access<br />

a<br />

the<br />

full<br />

P3P<br />

policy<br />

file.<br />

Solution:<br />

When<br />

the<br />

p3p-element<br />

is<br />

used<br />

to<br />

specify<br />

the<br />

location<br />

of<br />

a<br />

file<br />

containing<br />

the<br />

full<br />

policy,<br />

the<br />

browser<br />

attempts<br />

to<br />

access<br />

the<br />

file.<br />

The<br />

P3P<br />

specification<br />

does<br />

not<br />

require<br />

browsers<br />

to<br />

submit<br />

cookies<br />

with<br />

the<br />

request<br />

<strong>for</strong><br />

the<br />

full<br />

policy.<br />

Internet<br />

Explorer<br />

6<br />

does<br />

not<br />

submit<br />

a<br />

session<br />

cookie<br />

when<br />

accessing<br />

the<br />

full<br />

policy.<br />

This<br />

means<br />

that<br />

access<br />

to<br />

the<br />

full<br />

policy<br />

must<br />

be<br />

granted<br />

to<br />

unauthenticated<br />

users.<br />

When<br />

the<br />

browser<br />

receives<br />

either<br />

a<br />

login<br />

<strong>for</strong>m<br />

or<br />

a<br />

401<br />

error,<br />

modify<br />

the<br />

permissions<br />

on<br />

the<br />

full<br />

policy<br />

to<br />

allow<br />

access<br />

by<br />

unauthenticated<br />

users.<br />

68<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!