IBM Tivoli Access Manager for e-business
BEA WebLogic Server
kU H;-
v|
5.1
SA30-2210-00
IBM Tivoli Access Manager for e-business
BEA WebLogic Server
kU H;-
v|
5.1
SA30-2210-00
V!
L $8M L $8! vxOB &0 ; gkOb |!,71dLv G NO C :V GgW; ;P8JC@
JG(2003b 11y )
L 3$G : u 3$G! 05N mCO v JB Q, IBM Tivoli Access Manager( & 0 x# 5724-C08) G v | 5, 1. : 1, v$
gW 0 W pg DS 1.:M v$ gW! { kKOY .
© Copyright International Business Machines Corporation 2003. All rights reserved.
qw
-. ......................................vii
L % G gk Z ..................................vii
L % G ;k ..................................viii
| C -{ ....................................viii
1.: $8 ..................................viii
b; $ 8 ...................................ix
% 8H $ 8 ..................................ix
3 _Z |6- ..................................x
bz 8f 3m - .................................xi
|C -{ ...................................xi
BsN -{ W<: ................................xv
/ v W < : bI .................................xv
RA.~n v x .G ................................xv
L %! g k H T" ................................xvi
[Z< T" ..................................xvi
n5<& ! {% /v W fN ............................xvi
& 1 e R3 W 3 d ................................1
Tivoli Access Manager 8H p( ............................1
Tivoli Access Manager W WebLogic -v kU .......................2
Tivoli Access Manager Security Service Provider Interface 8:d R ..............3
Policy W *R h! ................................5
Z x W * R ..................................5
Tivoli Access Manager Nu gk ...........................6
N k W (g ...................................8
EZ:, !k :, )b 6$ !I : ............................8
& 2 e 3! v CgW ...............................11
v xGB C'{ ..................................11
p:) W ^p. d8gW ..............................11
g | 3! R A.~n ................................12
Tivoli Access Manager Policy Server .........................12
Tivoli Access Manager Authorization Server ......................12
Tivoli Access Manager WebSEAL GB Tivoli Access Manager Plug-in for Web Servers ......13
BEA WebLogic Server ..............................13
Tivoli Access Manager Java 18S .........................14
3 ! 6}g & gkO ) 3 ! .............................14
install_amwls IG ................................16
x C /?.< & g k O ) 3! .............................17
AIX! 3! ..................................17
HP-UX! 3! .................................18
Solaris! 3! .................................19
© Copyright IBM Corp. 2003 iii
Windows! 3! ................................20
& 3 e 8: } w .................................23
& 1 N : Tivoli Access Manager Java Runtime Environment 8: ................23
& 2 N : startWebLogic! kQ CLASSPATH 3 $ .....................25
& 3 N : Tivoli Access Manager for WebLogic 8: ....................26
Console Extension Web Application; gkO ) Tivoli Access Manager for WebLogic 8: ......26
mI`!- Tivoli Access Manager for WebLogic 8 : ...................28
& 4 N : Tivoli Access Manager |' 8: ........................29
Console Extension Web Application; gkO ) Tivoli Access Manager |' 8: .........29
m I`!- Tivoli Access Manager |' 8 : ......................30
& 5 N : BEA WebLogic Server L[ gN B 8 : .....................32
WebSEAL $G; gkO ) L[ g N B 8 : ......................32
Tivoli Access Manager Plug-in for Web Servers& gkO ) L[ gN B 8: ..........33
& 6 N : ,/: MH /f; wTO) BEA WebLogic Server Y _ -v /f! - Tivoli Access Manager for
WebLogic 8: ..................................34
& 7 N : 8: W:. ................................34
& 4 e L[ g N B g k !I ............................37
Tivoli Access Manager WebSEAL; gkQ L[ g N B ...................37
& 5 e |. B:) ................................39
Tivoli Access Manager Authorization Server!- N8 L2U . -q: g k .............39
Tivoli Access Manager for WebLogic!- g kZ W Wl |. .................40
% p nC .ILG gk ...............................41
gk A.....................................43
38 C5 NWB policy ...............................44
Tivoli Access Manager |' h& ...........................45
Tivoli Access Manager for WebLogic 8: X& ......................46
.&! Xa A ..................................46
g D b] N W N; gkOB L [ gN B G P ......................46
WebLogic -v! ^p. 9\! _}T ........................47
& Qg W ....................................47
K Ax .&! W.&Xa f} ............................48
& 6 e & E v CgW ...............................49
Solaris!- &E ..................................49
Windows!- &E .................................50
AIX!- &E ..................................50
HP-UX!- &E .................................51
N O A. /: D O |6 ...............................53
amsspi.properties .................................53
rbpf.properties ..................................55
amwlsjlog.properties ................................60
N O B. m I | % |6 ...............................63
AMWLSConfigure -action config ...........................64
iv IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
AMWLSConfigure -action unconfig ..........................66
AMWLSConfigure -action create_realm .........................67
AMWLSConfigure -action delete_realm .........................69
N O C. VGgW .................................71
s % ......................................73
k n ......................................75
v N ......................................83
qw v
vi IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
-.
IBM®Tivoli®Access Manager for BEA®WebLogic Server®(LDNB Tivoli Access
Manager for WebLogic)& gkOCT H M; / 5UOY . L &0 : IBM Tivoli
Access ManagerG bI ; .eO) BEA WebLogic Serverk8N [:H nC.I
LG ; vxUOY.
®
IBM
Tivoli®Access Manager(Tivoli Access Manager)B IBM Tivoli Access
Manager &0:!- n C.ILG ; G `OB % Jd Q b; R A.~nT OY . L &
0 : IBM Tivoli Access Manager n C .ILG ; k UO ) $|' Q G Q N) W
| . Vg G ; & x UOY. k U Vg G 8N GEGB L i & 0 : e-business n C .
I LG;'Q W.v) W n C .ILG 8H policy & _S }_ D8N | .O B W
<: &n |. Vg G; &xUOY.
®
V : IBM Tivoli Access ManagerB L| Tivoli SecureWay
Policy DirectorG u
Nn L'TOY. Tivoli SecureWay Policy Director RA. ~n W.-!- g
kQ
| . -v
& L&NM Policy ServerN N (OY.
L % G gk Z
IBM Tivoli Access Manager for WebLogic Server
g kZ H;-
!B BEA WebLogic
Server! VB IBM Tivoli Access Manager gk! kQ 3! , 8: W |. vCg
WL *M V@OY.
L % : Y = gk Z& ks 8N UOY.
v 8H |.Z
v W.v) C: [ |.Z
v IT 3hZ
gkZBY=! kX _ Km Vn_ UOY.
v HTTP, TCP/IP, FTP W Telnetz0:NM] AN d]
v WebLogic Server C:[G h! W |.
v Nu W GQ N)& w TQ 8H |.
SSL(Secure Sockets Layer) kE; gkOB f l , SSL ANd] , 0 3/ (xk W
3Nk), pvP /: , O#- K m.r W CA(Certificate Authority)! kX _ K m
V n_ UOY.
© Copyright IBM Corp. 2003 vii
L % G ;k
L % : Y =z0L 8:Gn V@OY.
v & 1 e ,“ R3 W 3 d”
Tivoli Access Manager for WebLogicL &xOB Nu W GQ -q: G 3d&
R 3UOY.
v & 2 e ,“ 3! vCgW″
Tivoli Access Manager for WebLogic; 3!OB f}! k X 3mUOY .
v & 3 e , ″8: }w ”
Tivoli Access Manager for WebLogic; 8:OB f}! k X 3mUOY .
v & 4 e ,“ |. B:)”
% C n C .ILG ; gk O B f}! k X 3m O m, gk A , .&! X a $8 W
&Qg W; &xUOY.
v & 5 e ,“ &E v CgW”
Tivoli Access Manager for WebLogic; &EOB f}! k X 3m UOY .
|C -{
n2 %L 5r L GBv G0OAi Tivoli Access Manager sLj/., U zPn
_ R % W |C %G 3m ; Kd OJC@. Jd Q %; G0 Q D BsN -{ W<
:! kQ v C gW; |6 O JC @.
IBM Tivoli Access Manager for e-business &0 Z<! k Q _! $8BY=!
- #; v V@OY.
http://www.ibm.com/software/tivoli/products/access-mgr-e-bus/
Tivoli Access Manager sLj/.BY=z0L 8:Gn V@OY.
v :1.: $8 ;
v ix dLv G :b; $ 8 ;
v ix dLv G :% 8H $ 8;
v x dLv G :3_ Z |6-;
v xi dLv G :bz 8f 3m - ;
1.: $8
v IBM Tivoli Access Manager for e-business Read This First(GA30-2205-00)
Tivoli Access Manager 3! W C[Ob! k Q $8& &x UOY .
v IBM Tivoli Access Manager for e-business
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
viii
3!Ob |!
(GA30-2206-00)
b; $ 8
R A.~n & Q g W , .& X a 8f 3 m W.- ;EgW z0 : VE $8& &
xUOY.
v IBM Tivoli Access Manager
Web Portal Manager NMd L:& wTQ Tivoli Access Manager b; RA.
~nG 3! W 8 : f} ! kX 3m U OY. L % : IBM Tivoli Access Manager
for e-business
for Business Integration W IBM Tivoli Access Manager for Operating Systems
M 0: b8 Tivoli Access Manager &0 z T2 g k Ob ' Q %TOY.
v IBM Tivoli Access Manager Base Administration Guide(SC32-1360-00)
Tivoli Access Manager -q: g k! kQ 3d W }w! kX 3m U OY.
pdadmin mI; gkO ) Web Portal Manager N Md L :!- B :) & v`O
B $8& & xU OY .
% 8H $ 8
v IBM Tivoli Access Manager for e-business
Tivoli Access Manager b; RA.~n W % 8H 8:d R! kQ 3! , 8:
W &E vCgW; &xUOY. L % : IBM Tivoli Access Manager
H;-
v IBM Tivoli Access Manager Upgrade Guide(SC32-1369-00)
% 8H 3! H;-
G v[ <. TOY.
b; 3! H; -
(SA30-2207-00)
G -j <.Lg, IBM Tivoli Access Manager
% 8H 3! H;-
(SA30-2208-00)
b; 3!
Tivoli SecureWay Policy Director v| 3.8 GB Tivoli Access Manager GL
| v |; Tivoli Access Manager v | 5.1N wW 9 LeOB f} ; 3mUOY.
v IBM Tivoli Access Manager for e-business WebSEAL Administration
Guide(SC32-1359-00)
WebSEAL; gkO ) 8H % 5^ NG Zx ; |.OB [w! |Q iWs ne
Za, |. }w W bz |6$8& &xUOY.
v IBM Tivoli Access Manager for e-business IBM WebSphere Application Server
kU H;-
Tivoli Access Manager& IBM WebSphere
(SA30-2209-00)
®
Application ServerM kU ! kQ
3 !, &E W | . v CgW; & xUOY .
v IBM Tivoli Access Manager for e-business IBM WebSphere Edge Server
(SA30-2211-00)
H;-
kU
Tivoli Access Manager & IBM WebSphere Edge Server nC.ILGz k U !
kQ 3!, &E W |. vCg W; &x U OY.
v IBM Tivoli Access Manager for e-business Plug-in for Web Servers Integration
Guide(SC32-1365-00)
-. ix
% -vk C/W N; gkO ) % 5^ N 8H ;'Q 3!, |. }w W b z |
6$8& &xUOY.
v IBM Tivoli Access Manager for e-business BEA WebLogic Server
(SA30-2210-00)
Tivoli Access Manager& BEA WebLogic ServerM kU ! kQ 3! , &E W
| . vCgW; & x UOY.
v IBM Tivoli Access Manager for e-business IBM Tivoli Identity Manager
Provisioning Fast Start Guide(SC32-1364-00)
Tivoli Access Manager W Tivoli Identity Manager kU! |CH B:)G 3
d& &xO m Provisioning Fast Start ]:GG g k W 3! f}; 3mUOY.
3_Z |6-
v IBM Tivoli Access Manager for e-business Authorization C API Developer
Reference(SC32-1355-00)
Tivoli Access Manager GQ N) C API W Tivoli Access Manager -q: C
/WNNMdL:& gkO ) Tivoli Access Manager 8H ; nC.I LG! _
!OB f}; 3m O B |6 Za& & x UOY.
v IBM Tivoli Access Manager for e-business Authorization Java Classes Developer
Reference(SC32-1350-00)
G Q N) APIG Java
Manager 8H; gkOB f} ! kX |6$8& &xUOY.
kU H;-
™
pn 8v; gk O ) n C .ILG L Tivoli Access
v IBM Tivoli Access Manager for e-business Administration C API Developer
Reference(SC32-1357-00)
| . API & gkO) nC .ILG L Tivoli Access Manager | . B:) & v`
OB f}! k X |6$8& &xUOY. L .-!- B | . APIG C 8v! k
X 3m UOY.
v IBM Tivoli Access Manager for e-business Administration Java Classes Developer
Reference(SC32-1356-00)
GQ N) API G Java pn 8v; gk O) n C.ILGL Tivoli Access Manager
|. B:) & gkR v VB [w ! |Q |6$8& &xUOY.
v IBM Tivoli Access Manager for e-business Web Security Developer Reference
(SC32-1358-00)
CDAS(Cross-Domain Authentication Service), CDMF(Cross-Domain Mapping
Framework) W Password Strength pb! kQ | . W ANW ! V $8 & &x
U OY.
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
x
bz 8f 3m -
v IBM Tivoli Access Manager for e-business Command Reference(SC32-1354-00)
Tivoli Access ManagerM T2 &xGB mI ` /?.< W :)3 . ! |Q $
8 & &xUOY.
v IBM Tivoli Access Manager Error Message Reference(SC32-1353-00)
Tivoli Access Manager!- } :GB ^CvG 3mz Ge 6! & &xUOY .
v IBM Tivoli Access Manager for e-business Problem Determination
Guide(SC32-1352-00)
Tivoli Access Manager! |Q .&! G0 $8& & xUOY .
v IBM Tivoli Access Manager for e-business Performance Tuning
Guide(SC32-1351-00)
g kZ 9v:.. N $ G H IBM Tivoli Directory Server M T2 Tivoli Access
ManagerN 8:GB /f! |Q :I 6$ $8& &xU OY .
|C -{
L} !-B Tivoli Access Manager sLj/. M |CH -{; * -UOY.
Tivoli Software Library!-B white papers, datasheets, demonstrations, redbooks
W announcement lettersM 0: YgQ Tivoli .-& &xUOY. Y =%gL.!
- Tivoli Software Library& gkR v V@OY.
http://www.ibm.com/software/tivoli/library/
Tivoli Software Glossary !B Tivoli RA. ~ n ! |CH bz k n! $GG n V
@ OY. Tivoli Software Glossary BY ='!!- 5 nN8 < v V@OY. Tivoli
Software Library(http://www.ibm.com/software/tivoli/library/)! VB Glossary 5)
& )# JC@.
IBM Global Security Kit
Tivoli Access Manager B IBM Global Security Kit(GSKit) v| 7.0 ; kQ % L
M O#- bI; &xU OY. GSKit B /$ C' {! kQ IBM Tivoli Access
Manager Base CDM IBM Tivoli Access Manager Web Security CD, IBM Tivoli
Access Manager Web Administration Interfaces CD W IBM Tivoli Access Manager
Directory Server CD! wTGn V@OY .
GSKit P0vB 0 %L M#L: , xk -3Nk 0 V W Nu d; ;[:OB % g
kGB iKeyman 0 |. /? .< gsk7ikm ; & xU OY. Y= -{: Tivoli
Information Center % g L .! V B IBM Tivoli Access Manager &0 .-M 0
:}!- < v V@OY.
-. xi
v IBM Global Security Kit Secure Sockets Layer and iKeyman User’s
Guide(SC32-1363-00)
Tivoli Access Manager /f!- SSL kEL !IO5O h9OB W.v ) GB
C:[ 8H |.Z & 'Q $ 8& &xUOY.
IBM Tivoli Directory Server
IBM Tivoli Directory Server, v| 5.2 B gkO B n5 <&G IBM Tivoli Access
Manager Directory Server CD! wTGn V@OY .
V : IBM Tivoli Directory ServerB L|! Y =G L'8 N 1.:Gz x RA.~
nG uNn L'TOY.
v IBM Directory Server(v| 4.1 Wv| 5.1)
v IBM SecureWay Directory Server(v| 3.2.2)
IBM Directory Server v| 4.1, IBM Directory Server v| 5.1 W IBM Tivoli
Directory Server v| 5.2B pN IBM Tivoli Access Manager v| 5.1! GX v
x KOY.
IBM Tivoli Directory Server! |Q _ ! $8BY=!- # ; v V@OY.
http://www.ibm.com/software/network/directory/library/
IBM DB2 Universal Database
IBM DB2®Universal Database™Enterprise Server Edition, v| 8.1 : IBM Tivoli
Access Manager Directory Server CD!- &xGg IBM Tivoli Directory Server
™
R A.~n M T 2 3 !KOY. IBM Tivoli Directory Server, z/OS
G B OS/390
LDAP -v& Tivoli Access ManagerG gk Z 9v:.. N gkR f l DB2B J
v gWTOY.
DB2! |Q _ ! $8BY=!- # ; v V@OY.
http://www.ibm.com/software/data/db2/
IBM WebSphere Application Server
IBM WebSphere Application Server, Advanced Single Server Edition 5.0: gk
O B n5 <&G IBM Tivoli Access Manager Web Administration Interfaces CD
! wTGn V@OY. WebSphere Application Server B Tivoli Access Manager&
| .OB % gk G B Web Portal Manager NMd L :M IBM Tivoli Directory Server
& | .OB % gk G B % | . x; Q Y vxR v V5O UOY. Tivoli Access
Manager !B IBM WebSphere Application Server v$Q 2 5 JdO g , LB IBM
Tivoli Access Manager WebSphere Fix Pack CD!- &xKOY .
®
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
xii
IBM WebSphere Application Server! |Q _ ! $8BY=!- # ; v V@O
Y.
http://www.ibm.com/software/webservers/appserv/infocenter.html
IBM Tivoli Access Manager for Business Integration
IBM Tivoli Access Manager for Business Integration : 05N V.R v V B &
08N, IBM MQSeries
^Cv & &xUOY. IBM Tivoli Access Manager for Business Integration: [v
E nC.ILGz ,|H 0 & gk O) WebSphere MQSeries nC.ILG L As
L vCM + a: ; !v m % L M& [ER v V 5O UOY. WebSEAL W IBM
Tivoli Access Manager for Operating Systems, IBM Tivoli Access Manager for
Business Integration33 , IBM Tivoli Access ManagerG -q:& gkOB Zx |
.Z _ O* T OY.
IBM Tivoli Access Manager for Business Integration! |Q _ ! $8BY=!
- #; v V@OY.
http://www.ibm.com/software/tivoli/products/access-mgr-bus-integration/
®
v | 5.2 8H Vg G z IBM WebSphere ®MQ v| 5.3
IBM Tivoli Access Manager for Business Integration v| 5.1! kQ |C .-
B Tivoli Information Center % g L .! V @ OY .
v IBM Tivoli Access Manager for Business Integration
|. H;-
v IBM Tivoli Access Manager for Business Integration
(SA30-1825-01)
.&! G0 H;-
(GA30-2064-00)
v IBM Tivoli Access Manager for Business Integration
3!Ob |!
(GA30-1827-01)
v IBM Tivoli Access Manager for Business Integration Read This First
(GA30-2063-00)
IBM Tivoli Access Manager for WebSphere Business
Integration Broker
IBM Tivoli Access Manager for Business IntegrationGONN gkR v VB IBM
Tivoli Access Manager for WebSphere Business Integration BrokerB WebSphere
Business Integration Message Broker, v| 5.0 W WebSphere Business Integration
Event Broker, v| 5.0! kQ 8H Vg G ; &x U OY. IBM Tivoli Access
Manager for WebSphere Business Integration BrokerB Tivoli Access ManagerM
a UO) O# W G Q $8 b ; N u , _ S!- $ GH G Q W (g -q:& & x
T8Na JMS x3 /E; n C.ILG ; 8# OB 6[; UOY.
IBM Tivoli Access Manager for WebSphere Integration Broker! |Q _ ! $8
BY=!- # ; v V@OY.
-. xiii
http://www.ibm.com/software/tivoli/products/access-mgr-bus-integration/
IBM Tivoli Access Manager for WebSphere Integration Broker, v| 5.1! kQ
Y = |C .- B Tivoli Information Center % g L .!- g k R v V @ OY .
v IBM Tivoli Access Manager for WebSphere Business Integration Brokers
Administration Guide(SC32-1347-00)
v IBM Tivoli Access Manager for WebSphere Business Integration Brokers
Ob |!
(GA30-2194-00)
3!
v IBM Tivoli Access Manager for Business Integration Read This First
(GA30-2063-00)
IBM Tivoli Access Manager for Operating Systems
IBM Tivoli Access Manager for Operating Systems B 05N V.R v V B &0
8N, b; n5 <&!- &xOB h ~ L\! UNIX C: [!- GQ N ) policy C
` h~; & x U OY. IBM Tivoli Access Manager for Operating SystemsB
WebSEAL W IBM Tivoli Access Manager for Business Integration33 IBM Tivoli
Access ManagerG -q:& gkOB Zx |. Z _ O* TOY .
IBM Tivoli Access Manager for Operating Systems! |Q _ ! $8BY=!-
# ; v V @OY.
http://www.ibm.com/software/tivoli/products/access-mgr-operating-sys/
IBM Tivoli Access Manager for Operating Systems v| 5.1G Y = .-B Tivoli
Information Center % g L.! V@OY .
v IBM Tivoli Access Manager for Operating Systems
v IBM Tivoli Access Manager for Operating Systems
v IBM Tivoli Access Manager for Operating Systems
(SA30-1842-01)
v IBM Tivoli Access Manager for Operating Systems
v IBM Tivoli Access Manager for Operating Systems Read Me(GA30-1844-01)
IBM Tivoli Identity Manager
IBM Tivoli Identity Manager v| 4.5B 05N V. ! IQ & 08N , L& gkO
) g kZ( 9: g kZ ID W O# )& _S !- |.O m ANqzW(o , n C.IL G,
Z x GB n5 <& ! kQ W<:& &x G B kR)R v V @OY. Tivoli Identity
ManagerB Tivoli Access Manager Agent& kX Tivoli Access ManagerM kU
R v V@OY. Agent 8E! | Q Z< Q $8B IBM cg Z!T . G O JC@.
IBM Tivoli Identity Manager! |Q Z< Q $8BY=!- # ; v V@OY.
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
xiv
3!H; -
| .H;-
(SA30-1841-01)
(SA30-1840-01)
.&! G0 H;-
3!Ob |!
(GA30-1843-01)
BsN -{ W<:
/v W <: bI
http://www.ibm.com/software/tivoli/products/identity-mgr/
& 0 sLj/. G -{: Y = Tivoli software library! PDF G B HTML | D8
N in V@OY.
http://www.ibm.com/software/tivoli/library
& 0 sLj/.! W<:OAi Product manuals 5 )& )# JC @ . Tivoli Software
Information Center! VB &0 L'; #F )#JC @.
&0 -{: 3!Ob |!, 3! H; -, g kZ H;-, |. Z H;- W 3 _ Z |
6-& wTUOY.
V : PDF .-& N b R fl , Adobe Acrobat Nb k- s Z (DO → N b& )#i
%CJ)!- dLv! B_b& 1C O) Nb OJC@.
/ v W < : bI: E? L R m OE* C " eV n E< { a T LVB gkZ! R
A.~n & 0; gk R v V5O 5M]OY. L & 0!-B 86 b z; g kO)
NMd L:G R.& hm =vR v V@OY. GQ 6l : k E 08e& gkO)
W !H gkZNMdL:G pg bI ; 6 [ R v V @OY.
RA.~n v x .G
Tivoli &0! . & ! VB f l , IBM Tivoli Software Support ! .GR v V @O
Y. Y=% gL.!- Tivoli Support 5)& -/ IBM Tivoli Software Support &
| 6OJC@.
http://www.ibm.com/software/support/
vxL J dQ f l, Y=% gL. !- IBM Software Support Guide ! 3mQ f
}; gkO ) RA. ~n v x! .GOJC@.
http://techsupport.services.ibm.com/guides/handbook.html
' -{: .&! G I"5! {% IBM Software Support! . GOB f} W Y =
z0: $8& &xUOY.
v nO W {U:
v gkZ! SQ 9 !G|-x # W |Z lm VR
v vx; d;Ob | ! KF_ R $8
-. xv
L %! g kH T"
L %!-B / v kn M 6!, n5<&0 mIzfN! kX ) / T"; gkUO
Y.
[Z< T"
L %!-BY=z0: [ Z< T" L gkKOY.
= T X:. ;! % C GB R.Z W k R.Z %U mI, 0 ve, E3/v , I G,
b oSC
pk:dL :
n5<& ! {% /v W fN
Java ,!: L' W @j'.B =T % C KOY .
/v, -{ &q, - 6OB }L* \n B
X:. ;! % CGB p: d., DO , bB , mI`, Ze 9& , C: [ ^C
v, TBX_ OB X:. W Nv* GB mI I G : pk:dL :N %C
KOY.
boSC
N %CKOY.
L %!-B p:d. %b W /f / v v$ ! UNIX T" ; gkUOY. Windows
mI; gkR f lB, /f /v G $variable ; %variable% N YYm, p :d . fN
G =!C(/)& i =!C(\)N YY JC@. Windows C:[!- bash ) ; gkR f
l, UNIX T"; g kOJC @.
xvi
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
& 1 e R3 W 3d
Tivoli Access Manager for WebLogic: Tivoli Access ManagerG 8H bI ; g
kO ) BEA WebLogic Server nC.ILG! kQ W <:& 8#OB Tivoli Access
Manager! kQ . eTOY . BEA WebLogic Server Security Service Provider
Interface& gkR f l , Tivoli Access Manager for WebLogic: Tivoli Access
Manager!|.OB gkZ 9v:. .& gkO ) ,sLp. & NuUOY.IBM
Tivoli Access Manager WebSEAL(WebSEAL) GB IBM Tivoli Access Manager
Plug-in for Web Server& gkO ) O] gkZ L[ gN B! kQ v x; &xO
5 O Tivoli Access Manager for WebLogicG 8H bI ; .e R v V @OY .
Tivoli Access Manager for WebLogic; gkO ) WebLogic -v nC.IL G:
Z y GB h !& /fRJdxL Tivoli Access Manager 8 H ; g k R v V@O
Y.
Tivoli Access Manager for WebLogic; 3!Ob |! Tivoli Access Manager 8
H 5^N; h!X _ UOY.
Tivoli Access Manager! MwOv J : g kZB 8H 5^ N; h!Ob | ! Tivoli
Access Manager 8H p(; KdX _ U OY . )b !B 8H p( ! kQ # \Q d
` L &xKOY.
Tivoli Access Manager 8H p(
Tivoli Access ManagerB v*{8N PjH N.s] W M:.s] ! V B Zx ;
6 zOT 8# X VB O | Q G Q W W.v) 8H policy |. Vg G T OY.
Tivoli Access ManagerB V7 \G 8H policy |.& & xUOY . GQ Nu , GQ ,
% LM 8H, Z x |. bI ; vxUOY. Tivoli Access Manager & % X N M] b
] nC.ILGz T 2 gk O ) El H |Om _ |.GB N .s] W M:.s]
; teR v V@OY.
Tivoli Access Manager BY=; &xUOY.
v Nu A9 S v)
Tivoli Access ManagerB Nu , b; Nu , gD W HTTP lu& w TQ $|'
Q Nu ^?O r ; vx UOY.
v GQA9Sv)
Tivoli Access ManagerB GQ policy |.& 'QA9Sv)& &xUOY. G Q
policyB _S!- |.G g #MAsL n |< G W<: {k v!8N Z? Ph
© Copyright IBM Corp. 2003 1
K OY. Tivoli Access Manager GQ -q: B xC Tivoli Access Manager -v
W -eD<(third-party) nC.IL GG W <: d;! kQ
OY .
WebSEAL:% b] Zx! kQ Tivoli Access Manager Zx 8H |. ZTOY .
WebSEAL: 8# %Zx! <P-H 8H;{kOB m: I V<:9e % -v T
OY .
Tivoli Access Manager Plug-in for Web ServersB Tivoli Access ManagerM k
UO ) %ZxG|< 8H VgG ; &xUOY. L C/W N: % -vM ?OQA
N<:G D. N 6[O) 5x OB " d; ;NMA.Om G Q a$L JdQv )
N & a$O g Jd O i gkZNu v\; & xUOY.
Tivoli Access Manager Plug-in for Web Servers W WebSEAL; QY L[ g N
B Vg G ; &xO m % nC.I L G Z x ;ZEG 8H policy! kU C 3 v V
@OY.
IBM Tivoli Access Manager! kQ .-& Kd O ) h! a$; ;.B % J dQ
$8& wTO) Tivoli Access Manager! k X u Z< OT ho v V@OY. L
%G -.!B |C Tivoli Access Manager .-G qO L wTGn V@OY.
ck WEN
& a$U
Tivoli Access Manager W WebLogic -v kU
Tivoli Access Manager for WebLogic, v| 5.1: Y =; vxUOY .
v BEA WebLogic Server v| 7.0 SP2
v BEA WebLogic Server v| 8.1 SP1
Tivoli Access Manager for WebLogic v| 5.1: SSPI(Security Service Provider
Interface)& gkO ) BEA WebLogic Server! kQ |< 8H A9S v)& &x
U OY.
V : Tivoli Access Manager for WebLogic v| 5.1 : BEA WebLogic Server g
kZ $ G | '& v xOv J@OY. BEA WebLogic Server g kZ $ G | '
! kQ v x: Tivoli Access Manager for WebLogic v | 4.1 G D. TOY.
BEA WebLogic ServerB -e D< (thrid-party) 8H &xZ(9: Tivoli Access Manager
for WebLogic)G SSPI& &xO) ZE G 8H bI ; BEA WebLogic Server 8
6 !O|w kUC 5 OY.
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
2
Tivoli Access Manager Security Service Provider Interface 8:d
R
Tivoli Access Manager for WebLogic:[:H b;8H |'& " BEA WebLogic
Server 8H 5^Nz YY m Y =z0: BEA WebLogic Server 8H &x Z& &
x UOY.
v Nu&xZ
v GQ &xZ
v *R J N &xZ
Tivoli Access Manager for WebLogic: b; BEA WebLogic Server GQ $8
J N 8H &xZ W b ; 0:d n & gkUOY.
'! * -H " & x ZB GQ WebLogic \V ; kX 8: m} ; R v VT OB
Management Bean(MBean); w TUOY . F!G}!-B Li " & x Z W
MBeanL &xOB b I! k X Z<w 3mUOY .
Tivoli Access ManagerBY= kU v!! BEA WebLogic Server& &x UOY.
Nu&xZ
Tivoli Access Manager for WebLogic Nu&xZB BEA WebLogic Server \ x
Nu ; 8vUOY . \x Nu!- g k ZB gk ZL' W O# 6U; gk O) BEA
WebLogic Server! kX Nu OA B C5& U OY . Tivoli Access ManagerB Tivoli
Access Manager Java 18S 8:d R& gkO ) L gk ZL' W O# & !KU
OY .
Tivoli Access Manager for WebLogic: GQ WebSEAL GB Tivoli Access Manager
Plug-in for Web Servers L[ gN B bI; &xO B % gk G B Z< N WN p
b ; &xUOY. L[ g N B bI g k !I ! kQ <Ng W : 37 d L v G & 4
e :L[ g N B g k !I; ! wTGn V@OY.
Tivoli Access Manager for WebLogic ! kQ Nu&xZB )/ 8: d RN L g
n . V@OY.
v Nu&xZ
IBM Tivoli Access Manager for WebLogic Server Nu&xZ& WebLogic 8
H A9Sv)! k U C5OY.
v JAAS(Java Authentication and Authorization Service) NWN pb
\x W L[ gN B Nu ; v`U OY. JAAS NWN pb : JAAS %XL v$
QA0C^(gkZ )N $vxV&&.OUOY. Tivoli Access Manager for
& 1 e R3 W 3 d 3
WebLogic:Z< NWN pb ; &xOB%, L pb : Tivoli Access Manager
Java 18S 8:d R& gkO ) Tivoli Access Manager Authorization Server!
k X Nu U OY .
v Nu MBean
WebLogic \V; kX Nu&xZ& 8:R v V5O UOY . G Q gk Z!
Tivoli Access Manager for WebLogic \V .e; gkO ) gk Z& _!O m
h &OB Mz 0: g kZ 9v:.. | . B :)& v`R v V 5O UOY.
GQ &xZ
G Q &xZB BEA WebLogic ServerM\N GQ - q : #GNMdL:& &xU
OY. GQ &xZ B BEA WebLogic Server Zx! kQ W<:! ckG Bv G B
E NGBv ) N & G 0 UOY . W<: a $: Tivoli Access Manager Java 18 S 8
:d R& gkO ) PhH PDPermission ,!: & gkO ) [ :KOY.
Tivoli Access Manager for WebLogic ! kQ G Q &xZ BY = 8:d R N L g
n. V@OY.
v GQ &xZ
GQ &xZ& WebLogic 8H A9Sv)! k UC5OY. Tivoli Access Manager
for WebLogic GQ &xZB BEA WebLogic Server Zx! kQ W<:& & n
R S8 FOs Tivoli Access Manager @j'. x# ! policy h! W Tivoli
Access Manager @j'. x# !- policy &E& 3 .UOY .
v GQ MBean
WebLogic \V; kX G Q &x Z& 8 :R v V5O UOY . WebLogic \V
; kQ policy [: W h&M 0 : 6 [; O5O #b I v 5 V@OY.
*R J N &xZ
* R J N &xZB * R; |. O B % g k GB BEA WebLogic Server M\ N G
Q -q: #GNMdL:& &xOB % gk K OY. * R JN &x ZB GQ &x
ZG % SN policy8YB *R ! _! ; SOY.
*R J N &xZBY=z0: 8:dRN Lgn. V@OY.
v *R J N &xZ
*R J N &xZ& WebLogic 8H A9S v)! kUC 5OY. Tivoli Access
Manager for WebLogic *R J N &xZB *RG h! W &E ! kQ %S;
!}OY.
v *R J N MBean
WebLogic \V; kX * R J N &x Z& 8 :R v V5O UOY . WebLogic
\V; kX * R ; h&O)*R 8:x;[: W ;EOB Mz 0: 6 [; O
5 O #b I v 5 V@OY.
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
4
Policy W *R h!
Policy W *R; h ! p:)3 M ! $GOE* WebLogic \V; kX [ :R v V
@OY. J2EE nC.ILG G h ! C, nC.ILG h ! p :)3 M ;! $GH *
R W policyB Tivoli Access Manager 8# @ j '. x#8N ] bKOY.
Tivoli Access Manager |. /? .<N pdadmin GB Tivoli Access Manager Web
Portal Manager& gkO ) policy& [:R vB V8* v `R vB x@ OY . Tivoli
Access Manager for WebLogic; gkOB BEA WebLogic Server& C[Ob |
! Tivoli Access Manager! n !v b; policy ! [:Gn_ UOY. L B Tivoli
Access Manager for WebLogic 8: _ v`K OY . Tivoli Access Manager for
WebLogic 8:! kQ <NgW: 23 dLv G & 3 e :8: }w;! * M V@O
Y .
Zx W *R
BEA WebLogic ServerB )/ 3G - N Y% Zx /| ; $ GO g , pN Tivoli
Access Manager for WebLogic! GX v xK OY . pg Zx /| : Tivoli Access
Manager for WebLogic ;!- ?OQ M 8N #V GGN , BEA WebLogic Server
G bD 1.:k 8 N [ :H u Z x / |5 Z ? 8 N vxKOY.
pg Zx /|! k X $ GH policy W *R: Tivoli Access Manager 8# @ j
'. x#! ?OQ fD 8N ze KOY.
vg 8#Gv Jm vx GB BEA WebLogic Server Zx qO : Y =z0@OY.
v |. Zx
v nC.ILG Zx
v COM Zx
v EIS Zx
v EJB Zx
v JDBC Zx
v JMS Zx
v -v Zx
v URL Zx
v % -q: Zx
Tivoli Access Manager 8# @ j'. x#!- Zx: Y = |D 8N %CKOY .
/WebAppServer/WLS/Resources/wls_domain /wls_realm /resource_type /Details
Tivoli Access Manager 8# @ j'. x#!- *R: Y = |D8N %CKOY .
/WebAppServer/WLS/Roles/wls_domain /wls_realm /role_name /AppName
& 1 e R3 W 3 d 5
Li Tivoli Access Manager 8# @ j'. AW LJ L': Tivoli Access Manager
for WebLogic 8N 8:H / : D O; gkO )O |w 8:I v V @OY. {s-
p g BEA WebLogic Server W b8 nC .ILG-v& ?OQ Tivoli Access
Manager 5^N ;! 8:R v V@OY . LB pg nC .I LG-v /| G *R
W policy! kQ }_H '!& [ : R v V5O U OY .
Tivoli Access Manager Nu gk
Tivoli Access Manager& gkO )\N gkZ GB ; N gkZ ! kQ Nu ; &
x R v V@OY . \N g k Z ! k Q Nu : WebSEAL GB Tivoli Access Manager
Plug-in for Web ServersG L[ g N B bI ! G8UOY . V{G W.v) 8H
;'X WebSEAL GB Tivoli Access Manager Plug-in for Web Servers & k X
\ N g k ZG W<: d ;; vEOB " WebLogic -vB ;N g k ZG W<: d
;; $COv ;F_ UOY. Y=}!-B \N g kZM ;N g kZ pN ! kX
Nu ; 3.OB f}! k X 3 mUOY.
WebSEAL; gkO )\N gkZNu
F ! YL n W%: 8# Z x! W <:OAB \N g k ZG d ;; 3 . O B p(;
8)]OY.
W2
1. Tivoli Access Manager
B \N g kZ ! kQ L[ gN B Nu ; &x U OY
Y= qO!- B 'G W2! %CH AN<: ! kX 3m U OY.
1. \N g k Z! 8# Z x! kQ W<:& d ;UOY . WebSEAL : #MAs L n
G 8H W.v)! i n!b |!d;; vEUOY
2. WebSEAL : gk ZG d;;N MA.O) Tivoli Access Manager 8H 5^N
!- Xg g kZ& NuUOY.
6 IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
.
WebSEAL: gk ZL' W O#, Nu- , gkZL' W RSA SecureID GB
gkZ $ GNu ^?O rGNu ^Re & vxUOY.
WebSEAL : d;H URL W Tivoli Access Manager W<: policy ! {s Z
< GQ a$;{kUOY. WebSEAL: mAg W( 9: h$ /?: , C# W Nu
^ ?Or);{kR v V@OY.
3. gkZG URL d;L GQ N )H D , WebSEAL:L& WebLogic -vN |
^U OY. d;! B \N g kZL'z b; Nu lu ; G /v O# ! wTK
OY. /v O#B sso_user! SOg Security Service Provider Interface!
WebSEAL; d; @.x 8N . NR v V5O UOY .
sso_user ! kQ Z< Q $8 B 23 dLv G & 3 e :8: } w;& | 6OJC
@.
4. WebLogic -vB NuH gk Z ID M O#& Security Service Provider Interface
N umOT |^ U OY.
5. Security Service Provider InterfaceB Tivoli Access Manager Nu -q:& g
kO ) WebSEALL &xQ O# ! ' ! 3mH sso_user ! kX CY% O#N
v K uUOY. o, L O#B d; @. xL WebSEAL LsB EZ& bJ N U
OY
L & GQ! k Q d; L XqGz@OY.
;N gkZNu
F!G Y L nW%!-B
m 8# Zx! W<:Ob 'Q d; ; 3.OB p( ; 8)]OY.
;N
g kZ! WebSEAL GB C/W N 8H ; kOv J
W2
2. Tivoli Access Manager Custom Realm
: ;N gk ZG Nu; &xUOY
& 1 e R3 W 3d 7
.
Y = qO!- B 'G W2! %CH A N<: ! k X 3m U OY .
1. ;N gkZ! 8# Zx! kQ W<:& d;UOY .
2. WebLogic gkZNu pbL gk ZG ID & Security Service Provider Interface
N 8@OY.
3. Security Service Provider InterfaceB Nu d; ; gk Z 9v:.. N 8@ O
Y .
N u L OaGi, Security Service Provider InterfaceB L gk ZL ';NuH
gkZN- WebLogic -v N .OUOY.
4. d;; GQ N )Ob 'X BEA WebLogic ServerB vgNuH gkZ(F6 5
GQL N)Gv J :)! d;H Zx! W<: R v V5O GQL N)GzBv
)N& G 0OB Tivoli Access Manager for WebLogic G Q &xZ !T 68U
OY.
W <:B Zx! k Q W <:! N)H * R; 1 COm v gNuH gkZ! L
/ Q *R L N)GzBv )N & a$ O B Tivoli Access Manager Authorization
Server!T #bO ) G0KOY .
Nk W (g
Tivoli Access Manager for WebLogic ;!- Nk: Tivoli Access Manager Java
18S 8:dR& g kO) PhH IBM JLog ,!:! GX 3.KOY. Tivoli Access
Manager for WebLogic W Tivoli Access Manager for WebLogicz T2 x^H
/:
JLog
OY . L8T Oi Tivoli Access Manager for WebLogic L WebLogic NW DO!
L%.& w" NWR v V@OY.
D O; BEA WebLogic Server Nk , !:& gkO5 O 8:R v V @
EZ:, !k :, )b 6$ !I :
Tivoli Access Manager for WebLogic: Tivoli Access Manager Java 18S , !
:& gkO ) Tivoli Access Manager 8# @j'. %LM #L : W gkZ 9v
:..& 6[UOY. ;N Tivoli Access Manager for WebLogic 3 CB W< : a
$ ! kQ : I bs; & xUOY.
Tivoli Access Manager Java 18S , !:B Tivoli Access Manager Authorization
Server @y 98& v xUOY .1w Authorization Server! UsI fl ,2w -v
! kQ @ y 98! Z? _}UOY.
GeGB /f 3$ : 9& acld W Tivoli Access Manager for WebLogic N8 L2
U . -q: & gkOB MT OY .
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
8
W <: a$: Tivoli Access Manager for WebLogic z T2 & x GB Tivoli Access
Manager Authorization Server N8 L2U . -q: GB Tivoli Access Manager
Policy Server& gkO ) v`R v V@OY .
Tivoli Access Manager Policy Server 8:: GP W :IG \O v! .& '.
! W:. /f !-8 g kX_ UOY. N8 L2U . -q: B ANvG /f !- g
kG5 O /$OT3_Gz@OY . Z<Q ;k : 39 dLv G : Tivoli Access Manager
Authorization Server!- N8 L2U . -q: g k;; |6OJC @.
& 1 e R3 W 3d 9
10 IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
& 2 e 3! vCgW
Le:Y= V&N 8:Gn V@ OY.
v :vxGB C'{ ;
v :p:) W ^p. d8gW ;
v 12 dLv G :g | 3! RA .~n;
v 14 dLv G :3! 6}g & gkO ) 3! ;
v 17 dLv G :xC / ?.<& gkO ) 3!;
vxGB C'{
Tivoli Access Manager for WebLogic, v| 5.1: Y =; vxUOY .
v BEA WebLogic Server v| 7.0 SP2
v BEA WebLogic Server v| 8.1 SP1
Tivoli Access Manager for WebLogic:L 1.:! kQ g kZ $ G | ' & vx
Ov J@OY . k E, L k U: BEA WebLogic Server SSPI(Security Service Provider
Interface)& vxUOY .
Tivoli Access Manager for WebLogic: Y = n5 <& !- v xKOY .
v IBM AIX 5.1
v Sun Solaris 8 W 9
v Hewlett-Packard HP-UX 11.0 W 11i(BEA WebLogic Server v| 7.08 )
v Microsoft Windows 2000 Server W Advanced Server(-q: Q 3)
V: Tivoli Access Manager for WebLogic: Java 2 Security Manager& gkO )
G `OB C: [; vxUOY. Java policy D O: Java 2 Security Manager G
/$ Ze#L:! [wOB % Jd Q G Q; wTOB R A .~n M T2 &xK
OY.
p:) W ^p. d8gW
Tivoli Access Manager for WebLogicG p:) W ^p. d8gW : Y=z0@
OY.
v 64MB RAM, 128MB GeJ
© Copyright IBM Corp. 2003 11
BEA WebLogic Server W b8 Tivoli Access Manager 8:d R! v$H J v
^p. L\! J d Q ^p. gTOY. _! 64MB RAM : 3L :I ; V { -O
B % gk K OY.
Y% Tivoli Access Manager 8:dR! J dQ ^p. g: #:. C:[! 3
!H Tivoli Access Manager 8:d R ! { s ^ s }OY . Z<Q $ 8B IBM Tivoli
Access Manager
v 2MB p:) x# , 4MB GeJ
BEA WebLogic Server W b8 Tivoli Access Manager 8:d R! J dQ p:
) x# L\! _ !N Jd Q x#TOY.
v NW DO! kX 5MB p:) x#
LB RA.~n 8 :d R! J dQ p:) x# L\! _!N J dQ x# TOY.
g| 3! RA.~n
Tivoli Access Manager for WebLogic G 3!& OaO A i Y = z0: g | 3!
RA.~n! Jd UOY.
v :Tivoli Access Manager Policy Server ;
b; 3! H; -
& |6OJC@.
v 13 dLv G : Tivoli Access Manager WebSEAL GB Tivoli Access Manager
Plug-in for Web Servers;
v 13 dLv G : BEA WebLogic Server;
v 14 dLv G : Tivoli Access Manager Java 18S;
Tivoli Access Manager Policy Server
Tivoli Access Manager for WebLogic; 3!Ob |! Tivoli Access Manager 8
H 5^N; 3$X _ UOY.
Tivoli Access Manager Policy Server& 3!R ' Tivoli Access Manager 8H 5
^ NL 3$KOY . L Policy Server B gkZ n5 < & G IBM Tivoli Access
Manager Base CD!- hwKOY .
O] {8N Tivoli Access Manager Policy ServerB Tivoli Access Manager for
WebLogic; cgO B C:[z Y% C:[! 3!K OY .
Tivoli Access Manager Authorization Server
Tivoli Access Manager Authorization ServerB BEA WebLogic Server W Tivoli
Access Manager for WebLogicL 3!H Mz ? OQ #:.! 3!Gn_ UOY .
Authorization ServerB BEA WebLogic Server! Tivoli Access Manager GQ -
q :! kQ W< :& &xUOY. Authorization ServerB G Q -v 0? 9Z e &
zeOb 'Q Nk W (g ] :G-v *R; UOY.
12
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
Tivoli Access Manager WebSEAL GB Tivoli Access Manager
Plug-in for Web Servers
Tivoli Access Manager WebSEAL(WebSEAL) W Tivoli Access Manager Plug-in
for Web Servers(C/WN): Tivoli Access Manager for WebLogicL gkR v V
B % b] 8H - q :& &xU OY . Li nC.I L G L 3! OaGi BEA
WebLogic Server L[ gN B Vg G ; &xOB % gkR v V @OY .
WebSEAL GB C/WN: Tivoli Access Manager for WebLogic; 3!Ob 'Q
g | 3! R A.~n! F UOY. W/* L [ g N B Vg G ; d8R f l! B J
dUOY.
WebSEAL GB C/WN! k Q 3! vCg W ! k X- B IBM Tivoli Access
Manager for e-business
WebSEAL GB b8 AOC -v& gk O) BEA WebLogic Server!,aR f
l, L AOC -v! BEA WebLogic Server 8# Z x! W<:OB g kZG \ O
,t v! Nv . NX_ UOY . W<:& & QOAi BEA WebLogic Server ,a J
M & [:X_ U OY. ,a J M & gkO i W<: & &QOb ' Q * R ; gk O B
kE W.v) 9' !- Zx; 8#R v V @ OY. ,a JM [: ! kQ Z< Q ;
k : BEA WebLogic Server .-& |6OJC @ .
% 8H 3! H;-
& |6OJC@.
BEA WebLogic Server
Tivoli Access Manager for WebLogic; #:.R C:[! BEA WebLogic Server
! 3! W 8 :Gn_ UOY. BEA WebLogic ServerB startWebLogic mI; g
k O ) C[UOY.
BEA WebLogic ServerB AIX& &\Q pg vx C'{ ! J dQ Java Runtime
EnvironmentM T2 P hK OY . Tivoli Access Manager for WebLogic: ? OQ
JRE(Java Runtime Environment)& gkU OY . BEA WebLogic ServerG 3!& O
aOi JRE! k Q Tivoli Access Manager for WebLogic |&6 G ; f7C5OY .
AIXG IBM Java Runtime Environment
AIX C:[!- BEA WebLogic Server 7.0; gkOAi Tivoli Access Manager
for WebLogic; #:.R C:[! IBM Java Runtime Environment v| 1.3L 3
!Gn_ UOY. AIX C:[!- BEA WebLogic Server 8.1 ; gk O Ai Tivoli
Access Manager for WebLogic; #:.R C:[! IBM Java Runtime Environment
v | 1.4! 3!Gn_ UOY . Tivoli Access Manager for WebLogic :L i?O
Q v|G Java Runtime Environment& gk UOY.
& 2 e 3! v CgW 13
Tivoli Access Manager Java 18S
Tivoli Access Manager for WebLogic; #:.R C:[! Tivoli Access Manager
b ;G Tivoli Access Manager Java 18 S v | 5.1 /f ; 3! W 8 :X_ U O
Y.
Tivoli Access Manager Java 18S /f : Java b] Nu W G Q b I; &xU
OY. Java ,!:B BEA WebLogic Server! gkOB JRE(Java Runtime
Environment)& .eUOY .
Tivoli Access Manager for WebLogic; #:.R C:[! Tivoli Access Manager
Java Runtime Environment& 8:O b |! Tivoli Access Manager 8H 5^N;
.3X_ U OY.
Tivoli Access Manager Java Runtime EnvironmentB " vxG B n5 <& ! k
Q IBM Tivoli Access Manager Base CD! G X PhKOY. 3!! k Q Z< Q
;k: IBM Tivoli Access Manager
3! 6}g & gkO ) 3!
b; 3! H; -
& |6OJC@.
VG
L 3! 6}gB BEA WebLogic Server, v | 7.0 G b; 3! '!! kX-
8 vxKOY. BEA WebLogic Server, v| 8.1; g kOB f l,17dLv
G :xC /?.<& gkO ) 3!; G vCgW ; {#JC@.
install_amwls 3! 6}gBY= 8:d R & {} Q x-N 3! O m 8: O ) Tivoli
Access Manager for WebLogic Server C:[G 3$ ; \x- C5OY .
v Access Manager Java Runtime Environment
v Access Manager for WebLogic Server
install_amwls 6}g & gkO ) Tivoli Access Manager for WebLogic Server C
:[; 3!Om 8 :OAi Y = \h& { # JC@.
1. Tivoli Access Manager 9v:.. -v , Policy Server W Authorization Server
& LL 5 ^N! 3$_B v . NOJC@.
2. pg Jd Q n5 <& P!! 3 ! GzBv .NOJC@ . Z<Q $8B 11 d
Lv G :vxGB C'{ ;; |6OJC@.
3. 5n (b;* ) L\ G Y% pnN sB W ^Cv & 8A i 3! 6}g & G`O
|!
b
4. L C:[! BEA WebLogic Server! 3! W 8 :Gn V m BEA WebLogic
Server 5^NL [: GzBv .NOJC@ .
14 IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
pn vx P0 v& 3!X _ UOY.
5. Windows C:[!- G` _N pg ANW %; > a O JC@ .
6. BEA WebLogic Server& C[O JC@ .
UNIX /WLS_install_dir /user_projects/ domain_name /
startWebLogic.sh
Windows
C:\WLS_install_dir \user_projects\domain_name /
startWebLogic.cmd
7. BEA WebLogic Server WebLogic_install_dir/server/bin p:d.!- Y
= :)3.& G `O) CLASSPATH W PATH /v& 3 $ Q D WebLogic
.jars& CLASSPATH, bin W lib p:d.! _!OJC @ .
UNIX .setWLSEnv.sh
Windows
setWLSEnv.cmd
3! 6}g & G`Ob |! BEA WebLogic Server M T2 &xH Java G`
D OL C:[ fN!- G U ! V Bv . N OJC@.
8. AIX, HP-UX(BEA WebLogic Server 7.08 ), Solaris W Windows C'{k Tivoli
Access Manager Web Security CDG g. p :d.! VB install_amwls A
NW %; G`OJC @. BEA WebLogic Server ! b; '!! 3 !Gn Vv J
8i, Y = mI ; gkO ) 3! 6} g& G`X_ UOY.
install_amwls -is:javahome path
)b- pathB 6}g & g kQ 3!& v `OB % g kGB jreG'!TOY.
V:
a. #\w b; 3! * ; c D2 E * Z ? 3!& 'X install_amwls.
options.template DO; gkR v V@OY. Jd Q pg * ; wTC0
Ai #\w DO; m}OJC@.
v b;*; c D2Ai Y= m I ; gkOJC @ .
install_amwls -options install_amwls.options.template
v Z? 3!& v`OAi Y =; gkOJC @.
install_amwls -silent -options install_amwls.options.template
b. BEA WebLogic ServerM T2 &xGB JDK& gkR ' q 5n C'{G
3 ! 6}gB C[ - i ! O|Gv JB X:. & %C R v V@OY. L
%C .&B G& R A.~n 3! !5b; Vv J@OY. L .&! ; $$
OAi, IBM JDK 1.3.1; 3! Om L& gk O) install_amwls& G `O
JC@.
& 2 e 3! v CgW 15
3! 6}g! C[Gn 16 d Lv G :install_amwls I G;! 3mH kN 8 :
$ 8! kQAR A. & % C U OY . \ Windows C: [!-B Tivoli Access
Manager for WebLogic! kX b; 3! p:d.& $ C X_ U OY .
V : L $8& & xOi(GB b; * ; $COi), u L s 3 T Gv Jm 8:d
R! 3!Gm 8 :KOY.
3! 6}gG G !!B 3!H 8 :d R, C5H 8 :gW W Oa )N& 8 )
VB d` -iL %CK OY. 3!! OaGz v8 8:L GPH fl,23dL
vG & 3 e :8: }w; G \h! {s Tivoli Access Manager for WebLogic
; v? 8N 8:OE* Y = \h& hSv`R v V@OY.
9. BEA WebLogic Server& _vOJC@ .
10. 3! ANW %L AMSSPIProviders.jar D O; /bea_install_dir/weblogic/
server/lib/mbeantypes p:d.! 9g_Bv!KOJC @. L p:d. ! X
g DOL 8 gOv J ; fl, /amwls_install_dir /lib !-v?8N D O;
9 gOJC@.
11. 25 dLv G :& 2 N : startWebLogic! kQ CLASSPATH 3$;G vCgW
! {s startWebLogic mI ! kQ CLASSPATH& 3$ OJC @.
12. Tivoli Access Manager |'& [:O) 8 :OJC@ . vCgW! k X-B 29
d Lv G :& 4 N : Tivoli Access Manager | ' 8:; ; |6OJC@.
13. WebLogic \V; gkO ) BEA WebLogic Server& YCC[OJC@.
14. Tivoli Access Manager WebSEAL; gkO ) BEA WebLogic Server! k
Q L[ gN B -q :& &x O Ai 32 dLv G :& 5 N : BEA WebLogic
Server L[ gN B 8:;G v CgW! {# JC@ .
15. 34 dLv G :& 7 N : 8: W:.;G \h& OaO ) 3! W 8:; W:.
T 8Na Tivoli Access Manager for WebLogic L Tivoli Access Manager 9
v :..! kX C YN 8:GzB v .NOJC@.
install_amwls IG
install_amwls & G`R ' Y= IG L % C KOY.
%
1. install_amwls
8: I G3m b;*
x ] ACL g k Z*
sec_master O# * Tivoli Access Manager |.Z O#
Policy Server #:. L' *
3! 6}g 8 : I G
Authorization ServerM kEOb ' X [
:H Tivoli Access Manager A0C^ (g
k Z)
Policy ServerG O |Q #:. L'. 9 &
i i, Y=z0@OY .
pdmgr.tivoli.com
16 IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
%
1. install_amwls
Policy Server w. x# *
Authorization Server #:. L' *
Authorization Server w. x# * Authorization Server w. x# 7136
TrueN 3$R fl AMWLS5.1 \V .e
h!
WebLogic 5^N | .Z *
WebLogic 5^N | . O# * WebLogic 5^N | .ZG O#
Access Manager for WebLogic Server 3
! p:d. f N
WebLogic Admin ServerG URL t3://localhost:7001
3! 6}g 8 : I G(hS
Policy Server! d;;NDOB w. x
# . b; w. x # B 7135T OY .
Tivoli Access Manager Authorization
Server #:. L'
BEA WebLogic Server 5^NG | .Z .
L gk Z B WebLogic 5^ N; [ :R
' .3Gz@OY .
Windows
UOY
)
C:[!-B b;*; g kX_
.
7135
true
C:\Program Files\Tivoli\pdwls
xC /?.<& g kO ) 3!
n5 <& ! {s Xg } ! VB vCgW ; {#JC @.
v :AIX! 3! ;
v 18 dLv G : HP-UX! 3!;
v 19 dLv G : Solaris! 3!;
v 20 dLv G : Windows! 3!;
V: Tivoli Access Manager for WebLogic ; 3!Ob |! ]eC BEA WebLogic
AIX! 3!
Tivoli Access Manager for WebLogic; 3!Oi P0v 8 :!- D OL _bKO
Y. AIX! RA. ~n P0v& 3!OA i installp & g kOJC @. W1 Y= Tivoli
Access Manager for WebLogic; v? 8N 8:OJC@
V: Tivoli Access Manager for WebLogic;LL 3! W 8:Q sB! - YC 3
AIX! Tivoli Access Manager for WebLogic; 3!OAi Y = vCgW ; OaO
JC @.
Server& _vQ D 3!! OaG i YCC[OJC@.
!X_ R fl, l 1 L& 8 : X & Q Y= &E X _ U OY.50dLv G :AIX
!- &E;& | 6OJC @.
1. rootNNWNOJC@.
2. Tivoli Access Manager b;G Jv 8:d R& wTQ g| 3! RA.~n!
3 !Gn VBv . N OJC@.12dLv G :g | 3! R A .~n;& |6OJC
@.
& 2 e 3! v CgW 17
3. IBM Tivoli Access Manager Web Security for AIX CD& CD esLj! V 8
JC @.
4. ) AR A.! Y= mI ;TBOJC@.
installp -acgNXd cd_mount_point /usr/sys/inst.images PDWLS
V : 3! ANW % L AMSSPIProviders.jar D O; /bea_install_dir /
5. W1 Y= Tivoli Access Manager for WebLogic ; 8:OJC@ .23 dLvG
& 3 e :8: }w;N L?OJC@
HP-UX! 3!
VG
HP-UX C'{! 3! R ' Tivoli Access Manager for WebLogic: BEA
WebLogic Server v| 7.0! kX-8 v xKOY .
weblogic/server/lib/mbeantypes p:d.! 9g_Bv!KOJC @. L
p:d.! Xg DOL 8g Ov J; f l /amwls_install_dir/lib !-v
?8N D O; 9gOJC@.
Tivoli Access Manager for WebLogic;LL 3! W 8:Q sB! - YC 3!X
_ R fl, l 1 L& 8 : X &Q Y= &E X _ UOY.51dLvG :HP-UX!-
&E;& | 6OJC@.
HP-UX! Tivoli Access Manager for WebLogic; 3!OAi Y = \h& OaO
JC @.
1. rootNNWNOJC@.
2. Tivoli Access Manager b;G Jv 8:d R& wTQ g| 3! RA.~n!
3 !Gn VBv . N OJC@.12dLv G :g | 3! R A .~n;& |6OJC
@.
3. pfs_mountd W pfsd! G` _Lv J8i iWsne !- Li ; wJk N C
[OJC@. pfs_mount mI 8N CD&6n.OJC @. 9& in, Y= mI;
TBOJC@.
/usr/sbin/pfs_mount /dev/dsk/c0t0d0 /cd-rom
)b- /dev/dsk/c0t0d0: CD pYL:L m /cd-rom : 6 n .wN.T OY.
4. Y= mI ;TBO) Tivoli Access Manager for WebLogic P0v& 3! OJ
C @.
# swinstall -s /cd_rom/hp PDWLS
18 IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
P . \h! OaGz=; *8; B ^Cv! % C K OY . G` \ h! C[J ; *
8;BY%^Cv! % CKOY. DOL CD!- _b Gn O ep:)! 3!K
OY . G` \ h! OaGz=; *8 ; B ^Cv! % C K OY . swinstall /?.
<! >aKOY.
V : 3! ANW % L AMSSPIProviders.jar DO; /bea_install_dir /
5. W1 Y= , Tivoli Access Manager for WebLogic ; 8:OJC@ .23 dLvG
& 3 e :8: }w;N L?OJC@
Solaris! 3!
Tivoli Access Manager for WebLogic; 3!Oi P0v 8 :!- D OL _bKO
Y. Solaris Operating Environment(LD Solarissm T )! RA. ~n P0v& 3
!OAi pkgadd & gk O JC @. W1 Y= , Tivoli Access Manager for WebLogic
; v? 8N 8:OJC@
weblogic/server/lib/mbeantypes p:d.! 9g_Bv!KOJC @. L
p:d.! Xg DOL 8 g Ov J; f l, /amwls_install_dir /lib !-
v ?8N D O; 9gOJC@.
V : Tivoli Access Manager for WebLogic;LL 3! W 8:Q sB! - YC 3
!X_ R fl, l1 L& 8 : X& Q Y= &E X_ UOY.49dLv G : Solaris
!- &E;& | 6 OJC @ .
Solaris! Tivoli Access Manager for WebLogic; 3!OAi Y = vCgW ; O
a OJC@.
1. rootNNWNOJC@.
2. Tivoli Access Manager b;G Jv 8:d R& wTQ g| 3! RA.~n!
3 !Gn VBv . N OJC@.12dLv G :g | 3! R A .~n;& |6OJC
@.
3. Solaris
IBM Tivoli Access Manager
% 8H
CD & V8JC@ .
k
4. RA.~n& 3 !OAi Y= m I ; G `O JC@ .
pkgadd -d /cdrom/cdrom0/solaris -a /cdrom/solaris/pddefault PDWLS
)b-,
-d /cdrom/cdrom0/solaris P0vG'!& v$ UOY .
-a /cdrom/cdrom0/solaris/pddefault 3! |. :)3.G'!& v$ UOY .
" P0v! kX 3! AN<: ! OaGi, Y= ^Cv ! %CKOY.
P0v 3!& Oa_@OY .
& 2 e 3! vCgW 19
V : 3! ANW % L AMSSPIProviders.jar D O; /bea_install_dir /
weblogic/server/lib/mbeantypes p:d.! 9g_Bv!KOJC @. L
p :d.! Xg DOL 8 g O v J; f l , /amwls_install_dir /lib !-
v?8N D O; 9gOJC@.
5. W1 Y= , Tivoli Access Manager for WebLogic ; 8:OJC@ .23 dLvG
& 3 e :8: }w;N L?OJC@ .
Windows! 3!
Tivoli Access Manager for WebLogic; 3!Oi P0v 8 :!- D OL _bKO
Y. Tivoli Access Manager for WebLogic DO; 3!OAi InstallShield setup.exe
& gkOJC @ . InstallShield! O aG i 23 dLv G & 3 e :8: } w; G vC
gW; gkO ) Tivoli Access Manager for WebLogic; 8:OJC @.
V : Tivoli Access Manager for WebLogic;LL 3! W 8:Q sB! - YC 3
!X_ R fl, l1 L& 8 : X& Q Y= &E X_ UOY.50dLv G
:Windows!- &E ;& |6OJC@.
Windows! Tivoli Access Manager for WebLogic; 3!OAi Y = vCgW ; O
a OJC@.
1. Administrator GQLVB gkZN Windows 5^ N ! NWNOJC @.
2. Tivoli Access Manager b;G Jv 8:d R& wTQ g| 3! RA.~n!
3 !Gn VBv . N OJC@.12dLv G :g | 3! R A .~n;& |6OJ
C@.
3. IBM Tivoli Access Manager Web Security for Windows CD& CD esLj
! V8JC @ .
4. Y= D O; N x -/ Tivoli Access Manager for WebLogic InstallShield 3
! ANW %; G `OJC@. )b- Y= mI !- E:B CD esLj& %C U
OY.
E:\Windows\PolicyDirector\Disk Images\Disk1\PDWLS\Disk Images\Disk1\setup.exe
3 ! pn 1 C "L -3OY.
5. Xg pn& 1C Q D .N; )#JC@ .
InstallShield ANW %L C [Gm /5 " L -3OY .
6. Y=; )#JC@ .
s L>: h` " L -3OY.
7. sL>: h` ;P:D h` 6 G! ?GOi 9 & )#JC @.
k s '! 1C " L -3 OY .
8. b@ '!& $COE* Y % '!& #F 8JC@ . Y=; )#JC@ .
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
20
D O 9g C [ "L -3OY.
9. %CH 3! '!! CY%v .N Q D Y=; )#JC@ .
D OL p:)N _b K OY. D OL 3!Gz =; K.B ^ Cv! % C KOY.
10. Oa& -/ 3! A NW %; > aOJC@ .
11. 3! ANW %L AMSSPIProviders.jar D O;
c:\bea_install_dir\weblogic\server\lib\mbeantypes p:d.! 9g_B
v! KOJC@. L p:d. ! X g DOL 8 g O v J; f l,
c:\amwls_install_dir\lib!-v?8N D O; 9gOJC@.
12. W1 Y= , Tivoli Access Manager for WebLogic; 8:OJC@ .23dLv G
& 3 e :8: }w;N L?OJC@ .
& 2 e 3! vCgW 21
22 IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
& 3 e 8: }w
Tivoli Access Manager for WebLogic; 8:OAi Y =G ""! 3mH vCgW
; OaOJC @.
v :& 1 N : Tivoli Access Manager Java Runtime Environment 8: ;
v 25 dLv G :& 2 N : startWebLogic! kQ CLASSPATH 3$;
v 26 dLv G :& 3 N : Tivoli Access Manager for WebLogic 8:;
v 29 dLv G :& 4 N : Tivoli Access Manager |' 8:;
v 32 dLv G :& 5 N : BEA WebLogic Server L[ gN B 8:;
v 34 dLv G :& 6 N : ,/: MH /f; wTO) BEA WebLogic Server Y_
-v /f! - Tivoli Access Manager for WebLogic 8 :;
v 34 dLv G :& 7 N : 8: W:.;
V: Le!-B Tivoli Access Manager b; 8 :dRG 8 :; wTO ) Tivoli
Access Manager for WebLogic W g| 3! RA.~n& 3!Q M 8N !$
U OY . L R A .~n& 3! O v JR 8i 11 d L v G & 2 e :3! v Cg W ;
; {s v] 3!OJC@.
& 1 N : Tivoli Access Manager Java Runtime Environment 8:
Tivoli Access Manager Java Runtime EnvironmentB Tivoli Access Manager for
WebLogicG g | 3! RA.~n TOY . Java Runtime 8:d R& CY #T 8:X
_ BEA WebLogic Server |'& 8:R v V @OY . Tivoli Access Manager /
? .< pdjrtecfg & gkO ) BEA WebLogic Server!- g kGB JRE(Java Runtime
Environment)& ;EO JC@ . GQ C:[!)/ Java 18SL wTH fl, BEA
WebLogic Server! gkQ JRE(Java Runtime Environment)& gkO ) pdjrtecfg
/ ?.< & G`OBv . N OJC@.
1. Tivoli Access Manager b; JRE(Java Runtime Environment)! 3!GzBv
.NOJC@.
Z<Q $8B 12 d Lv G :g | 3! RA.~n;& |6 OJC@.
2. BEA WebLogic Server WebLogic_install_dir/server/bin p:d.!- Y
= :)3.& G `O ) CLASSPATH W PATH /v& 3 $Q D CLASSPATH,
bin W lib p:d.! WebLogic .jars & _!OJC@.
UNIX .setWLSEnv.sh
Windows
setWLSEnv.cmd
© Copyright IBM Corp. 2003 23
ezInstall; G`Ob |! BEA WebLogic ServerM T2 &xH Java G` DO
L C:[ fN!- G U ! VBv . NOJC@.
3. Tivoli Access Manager Java Runtime EnvironmentB BEA WebLogic ServerM
T 2 &xG m 3!H JDK! k X 8:Gn_ U OY. L& v `O Ai Y=z0
L OJC@.
a. Tivoli Access Manager 3! fN! - p:d.& sbin p :d. N /fOJ
C@. 9& i i, Y=z0@OY.
UNIX: /opt/PolicyDirector/sbin
Windows: C:\Program Files\Tivoli\Policy Director\sbin
b. Y=z0L pdjrtecfg mI ; G`O JC@.
pdjrtecfg -action config -host policy_server_name -java_home java_location
)b- java_location : BEA WebLogic Server Java Runtime Environment G
p:d. '!TOY. p:d.G'!BY=z0@OY.
Windows
BEA WebLogic Server v| 7.0
c:\bea\jdk131_ob\jre
BEA WebLogic Server v| 8.1
c:\bea\jdk141\jre
Solaris, HP-UX
/usr/local/bea/jdk141_03
AIX
AIX C:[!- BEA WebLogic Server 7.0: IBM Java Runtime
Environment v| 1.3L Jd Om BEA WebLogic Server 8.1: IBM
Java Runtime Environment v| 1.4! Jd UOY . pdjrtecfg mI
G -java_home IG : AIX C:[! VB JRE G 3! '!N 3$
G n_ UOY. BEA WebLogic Server v| 7.0
/usr/java131
BEA WebLogic Server v| 8.1
/usr/java14
V:
1) BEA WebLogic Server 8.1 3!G pdjrtecfg /?.<B jre/lib p:
d.G jsse.jar ; Y_OY . L D O: Tivoli Access Manager Java
RuntimeL 8: X&I ' YC xsBN KOY .
2) Sun v1.4d JRE& 8:R ' , 8:L GPOGN pdjrtecfg& k- D pe
N G`OE* pdconfig /?.< & gk O ) JRE& 8: O v 6 JC @.
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
24
pdjrtecfg gk! kQ Z< Q $8 B IBM Tivoli Access Manager
! H;-
& |6OJC@.
& 2 N : startWebLogic! kQ CLASSPATH 3 $
V : Li 8: \h& G`O b | ! WebLogic 5^ N; [ :_Bv . N OJC@.
startWebLogic mI; gkO ) WebLogic -v& C[U OY . startWebLogic; g
kO )CY% Java ,!:! W< :Om NeR v V 5 O CLASSPATH /f /v &
v$X_ UOY.
Y = vCgW ; OaOJC @ .
1. WebLogic -v! G` _N fl _vOJC @ .
2. startWebLogic mIG CLASSPATH /v! Y = D OL'; _!OJC@.
UNIX
/opt/pdwls/lib/AMSSPICore.jar
/opt/pdwls/lib/rbpf.jar
Windows
b; 3
C:\amwls_install_directory \lib\AMSSPICore.jar
C:\amwls_install_directory \lib\rbpf.jar
startWebLogic mI: BEA WebLogic Server 3! 5 ^NG p:d .! V@
OY. %X 3!G fl Y=z0@OY.
UNIX /WebLogic_install_directory /user_projects/domain_name
Windows
C:\WebLogic_install_directory \user_projects\domain_name
/v domain_name: BEA WebLogic Server 5^ N; [ :R ' 1CQ L'T
OY .
3. b; pn (5n )& gkOB f l L \h & GJYJC@ .
pn Q; gkO )5 n(b;* ) L\ G pn & vxR f l , Y= fN &
startWebLogic :)3.! $GH CLASSPATH ! _!X_ UOY.
UNIX
/opt/pdwls/nls/java/com/tivoli/amwls/sspi/nls
Windows
C:\Progra~1\Tivoli\pdwls\nls\java\com\tivoli\amwls\sspi\nls
V : L p:d.& _!O i , pn Q 3! C /opt/pdwls/nls/java/com/
tivoli/amwls/sspi/nls/! 3!H Z x xi ! W<:R v V@OY.
& 3 e 8: }w 25
& 3 N : Tivoli Access Manager for WebLogic 8:
Tivoli Access Manager for WebLogic: mI` ; gkO ) 8:OE* Tivoli Access
Manager Console Extension Web Application; gkO ) 8:R v V@OY . L
iN !v IG ! kQ <Ng W : F! G} !-3mKOY.
BEA WebLogic Server 5^N: L/Q vCg W ; G`Ob |! [: Gn_ UO
Y .
Tivoli Access Manager for WebLogic; 8:Om | '& [:R ' TBGB % L
M B /: D O! ze K OY . Li /: D O: Tivoli Access Manager for WebLogic
G[?; /fOB % gkR v V@OY. Z<Q $8B 53 dL vG NO A :/:
D O |6;& | 6OJC@.
Console Extension Web Application; gkO ) Tivoli Access
Manager for WebLogic 8:
1. BEA WebLogic Server& C[O JC@ .
UNIX /WLS_install_dir /user_projects/domain_name /startWebLogic.sh
Windows
C:\WLS_install_dir \user_projects\domain_name \
startWebLogic.cmd
2. BEA WebLogic ; #:.OB C: [!- % jsl z & -m BEA WebLogic \
V!,aOJC@. o , Y= z0L ,a OJC @.
http://WebLogic_server_name :7001/console
7001: b; BEA WebLogic Server w. x#TOY . L * : 8: !IU OY .
3. BEA WebLogic Server NWB -iL %CK OY . |.Z GQ LVB BEA
WebLogic Server gkZNNWBOJC @.
4. Tivoli Access Manager for WebLogic Server& 8:Om Tivoli Access Manager
| '& [ :Ob | ! U z 8: B:)! kQ %N MdL:& &xOB Tivoli
Access Manager Console Extension Web Application; h!X_ U OY . L%
n C.ILG; h ! O Ai Y=; v `O JC@.
a. BEA WebLogic Server ( dLv G
; 1COJC@.
G
b. u % nC.I LG 8 : 5)& 1COJC@ .
5 ^N 8:
h J;!-
% nC.I L
c. jslz& kX wNe 5)& 1COJC@ .
d. nC.ILG amwls_install_dir\lib\AMWLSConsoleExtension.war; #F
8 JC@. wNe& )# JC @.
e. AMWLSConsoleExtension.war! kQ 1C 5)& )#JC @ .
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
26
f. h! ks; 1CQ D 8: W %C& )#JC@ .
Console Extension Web ApplicationL :x {8N h!GzBv!KOAi ^
J -i PR"G
zu& n!JC@.
% nC.I LG
zu& n!JC@.
h!
AMWLSConsoleExtensions ! qO! %CGn_ U OY. G Q \V % n C .
ILG . e; |3Oi \V "G ^J ! %CH BEA WebLogic Server =
v PR"! Tivoli Access Manager FL\ ; _ !U OY.
5. Tivoli Access Manager 5^N; 8:OA i BEA WebLogic Server =v PR
"G Access Manager F L\ ; )#JC@.
6. 8: -iL %CKOY . pg Jv $8 W 1C{ E3/v & TBOJC@ . TB
R $8! k Q vCg W : F! G % & |6 O JC@.
config 6!! g k !IQ IGL F! G % ! * -KOY. 9 x0 % !B
IGL * -KOY. N x0 % !B
Jv I G L' 3m
domain_admin WebLogic 5^N | .Z
domain_admin_pwd WebLogic 5^N | .Z O#
remote_acl_user Authorization Serverk8N [:GB Tivoli Access Manager A0C^
(gkZ )
sec_master_pass Tivoli Access Manager sec_master |.Z O#
pdmgrd_host Tivoli Access Manager Policy Server #:. L'
pdacld_host Tivoli Access Manager Authorization Server #:. L'
1C{
I GL * -KOY.
J v
V: O#B TBRJd! x8g kE 6! ! v`Gb | ! AR A.N %CKO
Y. L8T Oi O# ! m I w:d.! 2T Gv J @ OY.
Y= %! B config 6!! kQ
IG L' 3m
wls_server_url NC WebLogic -v ! k Q URL ; v$ UOY . b;*: t3://
localhost:7001TOY .
pdmgrd_port Tivoli Access Manager Policy Server w. x#
pdacld_port Tivoli Access Manager Authorization Server w. x#
am_domain Tivoli Access Manager 5^NG L'; v$ UOY . b;*: Default T
OY .
amwls_home Tivoli Access Manager for WebLogic Server 3! p:d.! kQ f N
& v$ UOY .
1C{
I GL * -KOY.
{ k; )#JC@.
7. 8:L OaGi , Tivoli Access Manager for WebLogic Server E3/v qOL
@ %J PR" ! %CKOY.
L& Tivoli Access Manager | '& 8:R v V@OY.29dLv G :& 4 N : Tivoli
Access Manager |' 8:; ; |6OJC@ .
& 3 e 8: } w 27
mI`!- Tivoli Access Manager for WebLogic 8 :
1. BEA WebLogic Server& C[O JC@ .
UNIX
/WLS_install_dir /user_projects/domain_name /startWebLogic.sh
Windows
C:\WLS_install_dir \user_projects\domain_name \startWebLogic.cmd
2. Tivoli Access Manager for WebLogic; 8:OAi Y = mI ; G`O JC@ .
V: DO _b _ Tivoli Access Manager for WebLogic L G eH '!! 3 !
Gv J: fl( L| e!-3mQ kN), AMWLSConfigure :) 3.G
AMSSPI_DIR /v& ]eCG& 3! p:d.G'!N 3$OJC@. 6y
!vN, WebLogicL b; '!! 3 !G v JR 8i, WLS_JAR /v &
ALWLSConfigure :)3.! VB WebLogic.jar G C Y % '!N ; E O
JC@.
UNIX install-dir/sbin/AMWLSConfigure.sh
Windows
install-dir\sbin\AMWLSConfigure.bat
Tivoli Access Manager for WebLogic; 8:O b 'Q AMWLSConfigure Java
n C.ILG! k Q mI ` 8.: Y = z0@OY.
v AMWLSConfigure -action config [options ...]
Tivoli Access Manager for WebLogic; 8:UOY .
v AMWLSConfigure -help [action ]
AMSSPIConfigureN |^Ob 'QJv W 1C{ * ; %C UOY.
config 6!! g k !IQ IGL F! G % ! * -KOY. 9 x0 % !B
IGL * -KOY. N x0 % !B
Jv I G L' 3m
domain_admin WebLogic 5^N | .Z
domain_admin_pwd WebLogic 5^N | .Z O#
remote_acl_user Authorization Serverk8N [:GB Tivoli Access Manager A0C^
(gkZ )
sec_master_pass Tivoli Access Manager sec_master |.Z O#
pdmgrd_host Tivoli Access Manager Policy Server #:. L'
pdacld_host Tivoli Access Manager Authorization Server #:. L'
1C{
I GL * -KOY.
J v
V: O#B TBRJd! x8g kE 6! ! v`Gb | ! AR A.N %CKO
Y. L8T Oi O# ! m I w:d.! 2T Gv J @ OY.
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
28
Y= %! B config 6!! kQ
IG L' 3m
deploy_extension trueN 3$R fl , Tivoli Access Manager for Web Logic Server \V
.e; h!UOY . b;*: true TOY .
wls_server_url NC WebLogic -v! kQ URL; v$ UOY . b;*:
t3://localhost:7001 TOY .
pdmgrd_port Tivoli Access Manager Policy Server w. x#
pdacld_port Tivoli Access Manager Authorization Server w. x#
am_domain Tivoli Access Manager 5^NG L'; v$ UOY . b;*: Default T
OY .
amwls_home Tivoli Access Manager for WebLogic Server 3! p:d.! kQ f N
& v$ UOY .
verbose Z<Q bB ; gk !I G B gk R!IO T OB N o * . b;*:
false TOY .
L& Tivoli Access Manager | '& 8:X_ UOY.
& 4 N : Tivoli Access Manager |' 8:
1C{
I GL * -KOY.
Console Extension Web Application; gkO ) Tivoli Access
Manager |' 8:
Tivoli Access Manager for WebLogic Server& BEA WebLogic ServerG 8H ;
& xO5O 8: Q D!B Tivoli Access Manager 8H z ,| C3 |'& [ :X_
UOY. L& v `OAi Y=z0L OJC@.
|'
1. ^J -i PR"G Access Manager F L\ ; n# D
@.
|'[:
2.
-iL %CKOY. pg Jv / v & TBOJC@. {k ; ) #JC@.
3. BEA WebLogic Server 7.0;'!- [:Q Tivoli Access Manager |'& g
k O5O 8: O Ai, Y=; v `O JC @ .
a. BEA WebLogic Server =v PR"!- gkZG 5^ Nz|CH FL\ ;
1 COJC@.
5^N 8:
b.
O]
c.
G!-
& 1COJC@.
-iL %CKOY.
b; |'
e S Yn q O ; gkO ) 'G \h!- [ :Q | '
{k
; )#JC@.
8H
G ; 1 C OJC@.
BEA WebLogic Server 8.1;'!- [:Q Tivoli Access Manager |'& g
kO5O 8: OAi BEA WebLogic Server \VG 8H G ; g kO ) b; |
'& 3$OJC@.
F L\ ; )#JC
4. BEA WebLogic Server & YCC[OJC@.
& 3 e 8: } w 29
5. u Access Manager |'! C YN bIO Bv W:.O Ai , @%J - i PR"
G Access Manager zu ;! VB
g kZ
Manager gkZ 9v:.. G Wq L wTGn V n_ UOY .
V : LL 8 g OB SSO gk Z & v$_ v 8 b8 gk Z ! kX $. O v J : O#
& TBQ fl, | '[: 6!! OaGbB O v8 SSOB %CG v J@OY.
L/Q fl, Tivoli Access Manager for WebLogic rbpf.properties D O!
- {}QWq; ; EO) SSO & 1T gk !IO T R v V @OY .
rbpf.properties ! kQ Z<Q ; k : 53 d L v G NO A :/: D O |6;
& |6OJC@.
mI`!- Tivoli Access Manager |' 8 :
1. Tivoli Access Manager for WebLogic |'& [:OAi Y = mI ; G`O J
C@.
V: DO _b _ Tivoli Access Manager for WebLogic L G eH '!! 3 !
Gv J: fl( L| e!-3mQ kN), AMWLSConfigure :) 3.G
AMSSPI_DIR /v& ]eCG& 3! p:d.G'!N 3$OJC@. 6y
!vN WebLogic L b; '!! 3 !G v JR E* WebLogic v| 8.1 ; g
k _N f l, WLS_JAR /v& ALWLSConfigure :) 3. ! VB
WebLogic.jarG CY% '!N ;EO JC@.
W
Wl
FL\! Tivoli Access
UNIX install-dir/sbin/AMWLSConfigure.sh
Windows
install-dir\sbin\AMWLSConfigure.bat
Tivoli Access Manager for WebLogic; 8:O b 'Q AMWLSConfigure Java
n C.ILG! k Q mI ` 8.: Y = z0@OY.
v AMWLSConfigure -action create_realm [options ...]
Tivoli Access Manager for WebLogic |'& [:UOY .
v AMWLSConfigure -help [action ]
AMSSPIConfigureN |^Ob 'QJv W 1C{ * ; %C UOY.
create_realm 6!! g k !IQ IGL F! G % ! * -KOY. 9 x0 % !
Jv
B
Jv I G L' 3m
realm_name [:Gm VB WLS |'G L'; v$ UOY .
domain_admin_pwd WebLogic 5^N | .Z O# & v$ UOY .
user_dn_suffix Console Extension Web Application; kX gk Z& [:R ' g
IGL * -KOY. N x0 % !B
kR 80 L'(DN) "Ln & v$ UOY .
1C{
I GL * -KOY.
30 IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
group_dn_suffix Console Extension Web Application ; kX Wl ;[ :R ' gk
R 80 L'(DN) "Ln & v$ UOY .
admin_group ;N 8: k5 ! g kR Tivoli Access Manager Wl; v$ UOY .
V: O#B TBRJd! x8g kE 6! ! v`Gb | ! AR A.N %CKO
Y. L8T Oi O# ! m I w:d.! 2T Gv J @ OY.
Y= %! B create_realm 6!! kQ
IG L' 3m
user_dn_prefix Console Extension Web Application; kX gk Z& [:R ' gk R 8
0 L'(DN) "Nn & v$ UOY .
group_dn_prefix Console Extension Web Application; kX Wl ;[:R ' gk R 8
0 L'(DN) "Nn & v$ UOY .
sso_enabled trueN 3$R fl L[ gN B vx; g k !IO T UOY . b; *:
false TOY .
sso_user Tivoli Access ManagerM L[ gN B EZ ,|;[:Ob ' Q gkZ
& v$ UOY .
sso_pwd L[ gN B gkZ ! kQ O#& v$ U OY .
verbose Z<Q bB ; gk !I G B gk R!IO T OB N o * . b;*:
false TOY .
1C{
I GL * -KOY.
2. BEA WebLogic Server 7.0;'!- [:Q Tivoli Access Manager |'& g
k O5O 8: O Ai, Y=; v `O JC @ .
a. BEA WebLogic; #:.OB C:[!- % jsl z& -m BEA WebLogic
\V!,aOJC@. o , Y= z0L OJC@.
http://WebLogic_server_name :7001/console
7001: b; BEA WebLogic Server w. x#Lg , L * : 8: !IU O
Y.
b. BEA WebLogic Server NWB -iL %CKOY . |.Z GQ LVB gk
ZNNWBOJC @.
c. BEA WebLogic Server =v PR"!- gkZG 5^ Nz|CH FL\ ;
1COJC@.
5 ^N 8:
d.
O]
e.
G!-
& 1COJC@.
-iL %CKOY.
b; |'
e S Yn q O ; gkO ) 'G \h!- [ :Q | '
{k
; )#JC@.
8H
G ; 1 C OJC@.
BEA WebLogic Server 8.1;'!- [:Q Tivoli Access Manager |'& g
kO5O 8: OAi BEA WebLogic Server \VG 8H G ; g kO ) b; 5
^N; 3$OJC@.
3. BEA WebLogic Server & YCC[OJC@.
& 3 e 8: } w 31
4. u Access manager |'! C YN bIO Bv W:.O Ai ^J PR "G Access
Manager zu ;! V B
Z 9v:.. G Wq L wTGn Vn_ UOY.
g kZ WW l
F L\! Tivoli Access manager g k
& 5 N : BEA WebLogic Server L[ gN B 8:
L}!-B WebSEAL G B Tivoli Access Manager Plug-in for Web Servers&
gkO ) BEA WebLogic Server ! kQ L[ gN B ; 8:OB AN <:! kX
3mUOY. L[ gN B 8 :; 8vOv J 8AB fl L};+CR v V @O
Y .
WebSEAL W Tivoli Access Manager Plug-in for Web ServersB 8H W L[ g
N B ; -N Y% f} 8 N 8vO m - N Y% C: [ 86 & gkU OY . WebSEAL
W % - v! kQC/WN; 3!OB % k Q $8B IBM Tivoli Access Manager
for e-business Web Security Installation Guide& |6OJC@. WebSEAL 8: !
k Q iWsne $8 W Z< Q ;k: IBM Tivoli Access Manager for e-business
WebSEAL Administration Guide& |6OJC@. C/WN! k Q n5 W 8: $
8 ! kX- B IBM Tivoli Access Manager Plug-in for Web Servers Integration
Guide& |6OJC@.
Y =}!-B 8vOA B 86 ! {s BEA WebLogic Server ! kQ L[ gN B
; 8:OB % Jd Q _! WebSEAL W C/ W N 8: $8& &xUOY.
v :WebSEAL $G; gkO ) L[ g N B 8 : ;
v 33 dLv G : Tivoli Access Manager Plug-in for Web Servers& gkO ) L[
gN B 8:;
WebSEAL $G; gkO ) L[ g N B 8 :
WebSEAL; gkO ) BEA WebLogic ServerG L[ g N B bI ; &xOAi
WebSEAL -v& #:.OB C:[! - Y= \h& OaOJC @ .
1. WebSEAL 8: DO webseald.conf& )JC @ .
2. Y= 8: Wq ; 3$OJC@ .
basicauth-dummy-passwd = sso_pwd
L O#B | '[ : 6! _ gk !IO T H sso_pwd J e G O# M O!X_
UOY.
3. WebSEAL; _vQ D YCC[O) 8: /fg W ;{kOJC @.
4. pdadmin mI; gkO ) WebSEAL $G;[:OJC@.
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
32
V : Tivoli Access Manager 8H 5^N! V B p g C:[!- L \h& v `
R v V@OY. WebSEAL C:[! -B L& G `R Jd! x@OY. 9&
i n, Tivoli Access Manager Policy Server C:[!- L& G `R v V
@OY.
-b IG; g k O) junction ks URL ; &xX_ U OY . LB L[ g N B!
JvTOY.
9& in, Y= mI;
pdadmin> server task webseald_server_name create -t tcp
-p WebLogic_Server_listen_port -h WebLogic_Server
-b supply junction_target
Q mI `!,SX-
T BOJC@.
Y = %!-B ' pdadmin mI G /v& $ G UOY .
%
2. pdadmin
IG3m
webseald_server_name WebSEAL -vGL'. LL': N NP (9 : webseald-
WebLogic_Server BEA WebLogic ServerG #:. L'
WebLogic_Server_listen_port BEA WebLogic Server! NDO m VB w. . b;*: 7001TOY .
-b supply L[ gN B! Jd UOY . WebSEALL uL O#& |^O5O O
junction_target junctionG URL ks
mI! kQ IG
WebSEAL_server_instance)8N Lgn}OY .
WebSEAL_server_instance!B C:[G #:. L'; gkO JC@.
9 & in, #:. C: [ L 'L cruz N f l webseald_server_name
: webseald-cruz TOY . V : )/ 3 G WebSEAL N:O :& ? O
Q -v! 3 !Q fl, X g -v N:O :5 v$ X _ U OY . Y_
-v N:O :& gkO ) junction ;[:OB % kQ vCg W: IBM
Tivoli Access Manager for e-business WebSEAL Administration Guide
& |6OJC@.
JC@.
WebSEAL junction [: W gk! kQ |< $8B IBM Tivoli Access Manager
for e-business WebSEAL Administration Guide& |6OJC@.
Tivoli Access Manager Plug-in for Web Servers& gkO ) L[ g
N B 8:
L [ gN B L CYN [ wOT O Ai Tivoli Access Manager Plug-in for Web
Servers! b; Nu lu! VB CY% $ 8& IBM Tivoli Access Manager for
WebLogic ServerN |^O5 O 8:X_ UOY . L8T O Ai , b; Nu ; C/ W
N 8: D OG gD GQ pbN 8 :X_ U OY.
plug-in_install_dir/etc p:d.! '!Q pdwebpi.conf 8: D O; m}O)
[common-modules] :DZ! Y = * ; _!O JC@.
& 3 e 8: }w 33
[common-modules]
post-authzn = BA
W 1 Y=, [BA} :D Z ! V B add-hdr W supply-password E3/v & "" BA
W sso_userG O#N 3$OJC@ . o , Y=z0L OJC@.
[BA]
add-hdr = supply
supply-password = sso_pwd
Tivoli Access Manager Plug-in for Web Servers 8:! kQ Z <Q $8B IBM
Tivoli Plug-in for Web Servers Integration Guide& |6OJC@.
& 6 N : ,/: M H /f; wTO) BEA WebLogic Server Y _ -v /f
!- Tivoli Access Manager for WebLogic 8 :
L}:BEA WebLogic Server! Y_ -v / f GB ,/: MH / f8N 3$G
n VB 86! k Q fl T OY. ,/: M H /f ; wTO ) BEA WebLogic Server
Y_ -v /f! - Tivoli Access Manager for WebLogic; 8 :OAi, Y=; v
`O JC@.
1. 26 dLv G :& 3 N : Tivoli Access Manager for WebLogic 8:; W 29 d
Lv G :& 4 N : Tivoli Access Manager | ' 8:; G vCgW; gkO ) Tivoli
Access Manager for WebLogic; 8:Om BEA WebLogic Server |. -v
!- Tivoli Access Manager |'& [ :OJC @ .
2. 5^N! kQ | . -vG Tivoli Access Manager for WebLogic /:; " k
s C: [(|. -v )! 9 g O) ,/: M 8: x ; w TQ |. -vG Tivoli
Access Manager for WebLogic; gk !IO T O JC@. /: D O:
BEA_WLS_HOME/jdk_location/jre/amwls/ ! '!Og "|. -vG ? O Q '
!! 9gGn_ UOY.
& 7 N : 8: W:.
Y = \ h& OaO) Tivoli Access Manager for WebLogic L Tivoli Access Manager
9v:..! kX CY N 8:GzBv K uOJC@.
1. BEA WebLogic Server \V; gkO ) u W:. gk Z& [:Om /? :;
KuOJC@.
2. Y= pdadmin mI ; G`O JC@ .
pdadmin> user show test_user
v account-valid! yesNv . NOJC@.
v password-valid! yesNv . NOJC@.
34
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
Tivoli Access Manager for WebLogic L[ gN B Vg G ; gkOi BEA
WebLogic Server! kX g kZ& u mOT NuOB WebSEAL; kX L[ Nu
\ h& v`R v V@ OY . %p nC .ILG ; G`O) N uL CYN 8: G z B
v .NR v V@OY. %p nC .I LG : 41 d L vG :%p nC .I LG gk;
! 3mGn V@OY.
& 3 e 8: }w 35
36 IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
& 4 e L[ g N B g k !I
Tivoli Access Manager WebSEAL; gkQ L[ g N B
Tivoli Access Manager for WebLogic: b8 Tivoli Access Manager &0(9 : Tivoli
Access Manager WebSEAL, Tivoli Access Manager Plug-in for Web Servers W
Tivoli Access Manager Plug-in for Edge Server)!-G%L[ gN B; v xU
OY .
WebSEALz BEA WebLogic Server #G EZ |hB 8:H HTTP b; Nu
dummy O#& gkO ) Lg n }OY. gkZ $ G 8 H |'NMdL:& 8vOB
L|G Tivoli Access Manager for BEA WebLogic Server &0!-B L[ g N
B; v`Ob 'X L/Q ? OQ f} ; g k_@OY.
Tivoli Access Manager HTTP *AOC(9: WebSEAL)B g kZL' W KAx L
[ gN B qP O#& | ^O5O 8 :KOY. L qP O# B *AOC!
VBv
#& KuQ D, Zx ; d;OB g k Z! kQ G Q $8! .8KOY.
G0OB % gk K OY. Tivoli Access Manager Authorization Server! O
EZ:L
F !G W2!-B E Z |h! .3GB f};Z<w 8)]OY.
W2
3. Tivoli Access Manager WebSEAL
; gkQ L[ g N B
'G W2!-BY= \h& 8)] OY.
© Copyright IBM Corp. 2003 37
1. gkZB WebSEALL vxOB Nu ^?O r (9 : gkZL'/O# GB , sL
p. Nu) ; gkO ) WebSEAL! kX NuUOY. W1 Y =, gk ZB BEA
WebLogic Server Zx! kQ d; ; &bUOY .
2. WebSEAL: -b supply IG ; gkO ) BEA WebLogic Server! kQ $G
8N 8:KOY. WebSEAL : Y =; wTOB b; Nu lu& gk O) BEA
WebLogic ServerN d;;|^U OY.
v WebSEAL Nu gk Z ID(YLnW%!- user-1 )
v webseald.confG basicauth-dummy-passwd. LB '!- p^H qP O#
T OY.
3. BEA WebLogic ServerB Ku;'X Tivoli Access Manager for WebLogic
Nu&xZ!T gkZ ID W q P O#& |^U OY.
4. Tivoli Access Manager for WebLogic NWN pb : Tivoli Access Manager
& gkO ) &xH O# ! Tivoli Access Manager for WebLogic 8: WebSEAL
L[ gN B gkZ ! kQ MNv Ku U OY. L O# G Ku : WebSEALz
BEA WebLogic Server #! EZ |h& & xUOY .
4\h& OaO i , Tivoli Access Manager for WebLogic Nu&xZB BEA
WebLogic Server! kX &xH g kZ ID& NuUOY . qP O# (YLnW%
!- ws-passwd )& g kOB 8:H WebSEAL L [ gN B g kZG N u:
Tivoli Access Manager for WebLogic NWN pb! 3C G b '.! Q x8 v
` GB !; Vv O JC@. L 3 C B 8: R v V8g (| 8 N 3 $ R v V@O
Y.
SSOB |'[: _ 3$R v Vv8 SSO Tivoli Access Manager for WebLogic
& v?8N gk !IO T O A i Y=; v`OJC@.
1. SSO gkZ& [:OJC @ .
2. amsspi.properties Tivoli Access Manager for WebLogic 8: DO! - Y
=; 3$OJC@.
com.tivoli.amwls.sspi.Authentication.ssoEnabled = true
com.tivoli.amwls.sspi.Authentication.ssoTrustId = sso_username
38 IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
& 5 e |. B:)
Le: Tivoli Access Manager for WebLogic! kQ Y = $8N 8:Gn V @ O
Y.
v :Tivoli Access Manager Authorization Server!- N8 L2U . -q: g k ;
v 40 dLv G : Tivoli Access Manager for WebLogic!- g kZ W Wl |.;
v 41 dLv G :%p nC .I LG gk;
v 43 dLv G :gk A;
v 44 dLv G : 38 C5 NWB policy;
v 45 dLv G : Tivoli Access Manager |' h&;
v 46 dLv G : Tivoli Access Manager for WebLogic 8: X&;
v 46 dLv G :.&! Xa A;
v 47 dLv G :&Qg W ;
Tivoli Access Manager Authorization Server!- N8 L2U . -q: g
k
Tivoli Access Manager for WebLogic : Tivoli Access Manager 8# @ j '. %
LM# L:!- 8# @j'.& #F 8Ai b ;{8N Tivoli Access Manager Policy
Server& gkUOY . W/* , L 86B Tivoli Access Manager Policy Server& 9
&R v x8g Tivoli Access Manager for WebLogic \ O GP v!; R3OGN
W :. /f!-8 g k Gn_ UOY. W [ !, N 8 L2U . -q:B ; N 3L b
z! {s u + 1 8S :I; !} OY. N8 L2U . -q: 86B Ws AN v G
/f!- g kGn_ UOY.
Y= 8: \h B Tivoli Access Manager for WebLogicL CYN 8:H D !8 v
` KOY. Tivoli Access Manager for WebLogic: N 3GN8L2U . -q:&
g kOg Li -q:B Q Y 8: H p g Tivoli Access Manager Authorization Server
!- g k !IO T Gn_ UOY.
v Tivoli Access Manager .e S: N8 L2U . -q:
LB Tivoli Access Manager Authorization Server& gkO ) PhH b ; N8
L2U . -q: TOY.
v RBPF 8# @ j'. #F 8b N8 L2U . - q:
LB Tivoli Access Manager for WebLogic ; gkO ) PhH N8 L2U . -
q:TOY.
© Copyright IBM Corp. 2003 39
Tivoli Access Manager for WebLogicLN8L2U . -q:& gk _ Nv . NO
A i Y= \ h & v`OJC@.
1. Tivoli Access Manager for WebLogic #:.!- Tivoli Access Manager
Authorization Server #:.N rbpf_ent_pos_browser x/ s Lj /.& 9g
Q D, C:[ PATH ! '! Q SGG p:d.! V 8 JC@.
rbpf_ent_pos_browser x/ s L j/.BY=G Tivoli Access Manager for
WebLogic #:.!- #; v V @OY .
UNIX /opt/PolicyDirector/lib
Windows
c:\Program Files\Tivoli\pdwls\bin
2. Tivoli Access Manager Authorization #:.!- Y='!! VB ivacld.conf
DO; )JC @.
UNIX /opt/PolicyDirector/etc
Windows
c:\Program Files\Tivoli\Policy Director\etc
3. [aznapi-entitlement-services] :DZ! Y = N s N; _!O JC@ .
AZN_ENT_EXT_ATTR = azn_ent_ext_attr
RBPF_POS_BROWSE = rbpf_ent_pos_browser
4. Tivoli Access Manager Authorization Server& YCC[OJC@.
5. Tivoli Access Manager for WebLogic #:.!- java_home/amwls/
WLS_Domain_Name/WLS_Realm_Name ! '!Q rbpf.properties DO; )JC
@. )b-, WLS_Domain_Name : BEA WebLogic Server 5^NG L'Lm
WLS_Realm_Name: BEA WebLogic Server 8H | 'G L'TOY. Y = /
:; trueN ;EO JC @.
com.tivoli.pd.as.rbpf.UseEntitlements=true
6. BEA WebLogic Server & YCC[OJC@.
Li \h! Oa Gi, Tivoli Access Manager for WebLogic gk !I BEA
WebLogic ServerB Tivoli Access Manager Policy ServerM ]kN Tivoli Access
Manager Authorization Server& gkO ) pg 8# @ j'. #F 8b & v`UO
Y .
Tivoli Access Manager for WebLogic!- g kZ W Wl |.
Tivoli Access Manager for WebLogic !- BEA WebLogic Server \V; gkO
) g kZ W Wl ; |.R v V@OY. BEA WebLogic Server \V G 8H PR
"!- Access Manager FL\; n# D
\; %C OJC@. Li F L\!- Tivoli Access Manager for WebLogic 8H !
k Q gkZ W Wl ; |. R v V@ OY .
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
40
|'
F L\ ; -/ gkZ W Wl F L
gkZ FL\ ; 1COi
`R v V@OY.
v Tivoli Access Manager for WebLogic gkZ& * -R v V@OY .
v 30 gkZG < NgW; %C R v V@OY.
v gkZ& [:R v V@OY.
gkZ |.
dLv! %CKOY. L dLv!- Y =; v
W l FL\ ; 1COi
v V@OY.
v Wl; *-R v V@OY.
v /$ WlG <NgW ; %C R v V@OY.
v Wl;[:R v V@OY.
|C \V .e d Lv! - xi8N 8PH q O ;TBO) Y_ g kZ& W l! _
!O E* Wl; gk Z! _ !R v V@OY.
gkZ GB Wl ; * -R '
! v$H b X; f 7OB pg g kZ GB Wl L %CKOY.
%p nC .ILG gk
% p nC .ILG ; gkO i , N !v /| G GQ 9 & & 8 m WebSEAL L[ g
N B bI ; ,@R v V@OY.
N !v /| G GQ : Y = z0 @OY.
v 1p
Wl |.
Vk .O
d Lv! %CKOY. L d Lv!- Y =; v`R
Je! *LTBGv J: fl,
PO
Je
h! p:)3 M& gkO) gkZ W Wl /$ *R; N )UOY.
v ANW %
n C.ILGR: Ze ;!- * R !KL v ` K OY.
%p nC .ILG:%8:d RM EJB 8:d RN Lgn. V@OY.
% 8:d R G N !v 8H 9 ' : Y =z0L 3mR v V@OY.
v 1p:
web.xml h! p:)3 MB ServletRoleLs B\O *R ; $ GUOY.
weblogic.xml h! p:)3 MB ServletRolez BankMembersServlet Wl #
G A0C^(gk Z ) JN ; $ G UOY. web.xml h! p:)3 M G 8H &Q 6
G : gk Z ! ServletG ^Re! W < :OA i ]eC ServletRole *R L N)G
n_ QYB M; *8 @ OY.
v ANW %:
& 5 e |. B:) 41
doPost() ^ReB L' #b Z ! ServletRole L N) G zBv ANW % 8 N .N
OB _! 8H b I; !} OY. L& gk Oi \O% 8:d R ;! ANW %
W 1 p 8 H ; Q Y W : . R v V @ OY . G Q ! K ; v `OA i
HTTPRequest.isUserInRole() ^Re & gkUOY.
EJB 8:d RG < !v 8H 9 ': Y = z0L 3mR v V@OY.
v 1p 8 H :
EJBRole LsB ejb-jar.xml h! p:)3 M ;! \O * RL $ G K OY .
weblogic-ejb-jar.xml h! p:)3 MB EJBRole Wlz BankMembersEJB
W l #G A0C^ J N ; $ G UOY. ejb-jar.xml h! p:)3 M G ^Re G
Q: gk Z! getBalance() ^Re! W <: OAi ]eC EJBRole * RL N
)Gn_ QYB M; *8 @ OY .
v ANW % 8H:
getBalance() ^ReB #bZ! EJBRoleL N)GzBv ANW % 8 N . N OB
_! 8H bI; !}OY . GQ ! K; v`O Ai EJBContext.isCallerInRole()
^Re & gkUOY.
v h$ L'! { % ANW % 8H:
getBalance() ^ReB d; H h$GL'L #b A 0C^(gkZ )GL'z O
!OBv .N U OY. o , Banker18 Banker1 G h$ k1:& < v V n_ U
OY.
%p nC .ILG ; G`OA i Y= \h & OaOJC @.
1. %p nC .ILG PDDemoApp.ear ;
WebLogic_domain_directory \applicationsN 9gOJC@. ]e C L p :d
.& gkRJdB x@ OY . EAR DO; D O C:[ G pgp:d.! Q v
V@OY. %p nC .I LG : AMWLS_install_dir/demo!- # ; v V@OY.
2. BEA WebLogic Server \V; gkO ) Y = gk Z& [:OJC@ .
Banker1
Banker2
Banker3
Banker4
URLUser1
URLUser2
URLUser3
3. N 3G Wl BankMembersEJB W BankMembersServlet;[:OJC @. uN [
:H Wl! g kZ Banker1, Banker2, Banker3 W Banker4& _!OJC @.
BEA WebLogic Server \V gk! kQ vC g W: BEA WebLogic Server .
-& |6OJC@.
4. BEA WebLogic Server \V; gkO ) %p nC . ILG ; h !OJC@ .
5. %p nC .ILG! W <:OA i Y= URL! W<:O JC @.
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
42
http://WebLogic_Server_host :WebLogic_Server_listening_port /pddemo/PDDemo
'! $ GH Banker gk Z _ O*N NuOJC@.
WebLogic_Server_hostB BEA WebLogic Server C:[G # :. L'T OY.
WebLogic_Server_listening_portB BEA WebLogic Server! ND _ N w. T
OY .
6. BankMembersServlet Wl! VB g kZ8 Servlet! W<:R v VBv K u
O JC@.
7. BankMembersEJB WlG 8:xNNuH gkZ! ZEG k1:& < v V
v 8 Y % gkZG k1: & < v xB v K u OJC@.
WebSEAL L[ gN B ; W :.OAi Y= \h & O a O JC@ .
1. Y= URL! W<:O JC @.
https://webseald_server_name /junction_target /pddemo/PDDemo
WebSEAL!-B NuOs B AR A.& %C U OY .
gk A
/ v webseald_server_name W junction_target ! kQ 3 m: 34 d L v G :&
7 N : 8: W:.;& |6O JC@ .
V : b; WebSEAL [? 8 N N X HTTP & kQ b ; GB gD b ] NuL ]
vGGN HTTPS& gkOJC @ .
2. '! $ GH gk Z _ O*N NuOJC@ .
L AN<:B gk Z& BEA WebLogic ServerN L[ g N BOg, N x0 N
u ; d8O v Jm Servlet; #bUOY. WebSEAL ; kX W <:Q fl,
PDDemo %p nC .ILG : BEA WebLogic Server! w" W<:R ' % C
G B Mz ? OQ [ ? ; 8)]OY.
3. NuH gk Z! ZE G\W; < v Vv8 Y % gk ZG \W: < v xBv
.NOJC@.
1. \N g kZ! L[ g N B; g kR ' 8H T";_v0JC @ . WebSEAL
-v8LNu; v`X_ U OY. L & v`OA i , ;N gk Z , o , WebSEAL
; gkO ) BEA WebLogic Server! W<:Ov JB gk Z BEA WebLogic
Server! W<:Ov x O5O OJC @. LB W.v) ,a JM& g kO) v
`R v V@OY. ,a JM& gk Oi W<: & & QOb ' Q * R; gk OB
k E W.v) 9' !- Z x ; 8#R v V @ OY .
2. Tivoli Access ManagerM WebLogic Server pN GPQ Nu C 5G ."; 8
8UOY. " &0: gk Z h $Labb |! c k !IQ V k C5 GP =v
& 5 e |. B:) 43
& v$OB 8H 8:3$;/v8vUOY. gkZ B N 3 $_ !- [: 3
$! GX aiOY. 9& in, WebLogic -v! 5xG NW N GP & c kO v
8 Tivoli Access Manager! < xG NW N GP 8 ckO 5O 8: H fl, g
kZB < x G NW N GP D aiOY.
38 C5 NWB policy
LDAP b] Tivoli Access Manager 3!! gk R v VB 38 C5 NWB policy &
gkOi Vk NW B C5 GP =v W dN < a] C#; v$ O ) D;M O# x
] ; 9fR v V @OY. Policy B NWB C 5 G P ! u 8invbn v O$ C #
kbX_ O B 6G;[:UOY. 9& in , policyB 38G GP C5& v C R v
V8g W Z!B 180JG dN <! Z{(OY . L NWB policy /| : D;M! S
GN }:OB NWB C5! 1J !)/ x_}Gv xOT R v V@OY.
3 8 C5 NWB policy & 3$OA i N 3G pdadmin policy mI 3$L Jd U O
Y.
v Vk NWB C5 G P =v
Vk NWN GP v3$ policy
v NWB C5 GP 3$ Jz ! kQ dN <
gk R!I C ##]3$ policy
d N < 3$: h $ a] C##]GB X g h$G O | gk R ! I ; wTR
v V@OY.
N WB policy! /$ a ] C# dN < ! N z GB 38 C 5 G P! kX 3$H f
l(9N-), W x0 C5 ( CY#E* CY#v J:) & O i, O# policy ' . ! h$
LSCN gk R!IT; *8 ; B @ y ^ Cv! % CKOY.
C##]: JN v$KOY. VR G e C##]: 60J TOY.
g k R!I C ##] policy! gk R!I8N 3$Gi, gk ZG Xg h $ La
\v m L gk Z! kQ LDAP /?Q h$ S: : FO@N 3$KOY. |.ZB
Web Portal Manager& kX h$; YC gk !I8N 3$ UOY .
V : gk R!I C ##] ; gk R!I 8 N 3$Oi _!|. @vle! _ }
UOY. /?Q h$ $8& C/WN! 9& R ' v,GB M; 8 T I v V@
OY . L/Q s2 : LDAP /f! {s Y (OY . W [! , /$ LDAP 8vL
/ ?Q h$ ;E 6[G az N :IL 3nv B M ; f hO T I v V@OY.
L/Q L/N C#J z#]; gkR M ; G eUOY.
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
44
Y = pdadmin mI : LDAP 9v:..! k X gk R '8 {} U OY .
%
3. pdadmin LDAP
policy set max-login-failures {number |unset} [-user username ]
policy get max-login-failures [-user username ]
policy set disable-time-interval {number |unset|disable} [-user username ]
policy get disable-time-interval [-user username ]
NWB
policy
mI
mI 3 m
dN <! N zGb | nv ck GB V k NWB C 5 G P =
v& &nOB policy & | .UOY . L mI: policy 3$
gk R!I C ##]mI! 3$H dN < ! {s a$ K
OY.
| .ZN- L policy & /$ gkZ ! T {kO E * LDAP
9v:..! * -H pg gkZ !T policy & |* 8 N {
kR v V@OY .
b; 3$: 108 C5 TOY .
V k NWB C5 G P =v ! 5 ^ Oi h$; gk R ! I
OT OB C# b #; &n OB dN < policy & | . UOY .
| .ZN- L dN < policy & /$ gkZ ! T {kO E *
LDAP 9v:..! * -H pg gkZ !T policy& [N
z N {kR v V @OY .
Tivoli Access Manager |' h&
Tivoli Access Manager |'& h&OA i Y =; v`OJC@ .
1. BEA WebLogic Server! C[GzBv . NO JC@ .
2. \V; gkO ) Tivoli Access Manager for WebLogic create_realm 6!N [
:Gv J: b; | '& /fOJC@.
3. BEA WebLogic Server& YCC[OJC@.
4. \V; gkO ) Tivoli Access Manager |'& h&OA i Y =; v `OJC@.
a. BEA WebLogic Server =vY!- Access Manager FL\ ; )JC @ .
b. |' FL\ ; )#JC@ .
c. h&& )#JC@ .
d. .N; )#JC@ .
5. mI`; gk O) Tivoli Access Manager |'& h&OA i AMWLSConfigure
-action delete_realm ; gkO JC@. AMWLSConfigure -action delete_realm
mI! g kR IG ! kQ Z< Q ; k: 63 d Lv G N O B : mI | % |6;
& |6OJC@.
b; 3$: 180J TOY .
|' 8:
|' 8: h&
|'[:
dLv! s JeM T2 %CKOY.
dLv! %CKOY.
dLv! %CKOY.
& 5 e |. B:) 45
V : DO _b _ Tivoli Access Manager for WebLogic L G e' !! 3 !Gv J
: fl, AMWLSConfigure :)3. G AMSSPI_DIR /v& ]eCG& 3!
p :d.G'!N 3$OJC@. 6y! v N , WebLogicL b; ' !! 3 !Gv
JR 8i, WLS_JAR /v & ALWLSConfigure :) 3 .! V B WebLogic.jar
G CY% '!N ;EO JC@.
Tivoli Access Manager for WebLogic 8: X&
Tivoli Access Manager for WebLogic; 8: X& OAi Y =; v`OJC@ .
1. BEA WebLogic Server! C[GzBv . NO JC@ .
2. Tivoli Access Manager |'! h&GzB v . NOJC@ .45dLv G :Tivoli
Access Manager |' h&;& | 6OJC@ .
3. \V; gkO ) Tivoli Access Manager for WebLogic; 8: X& OAi Y =
; v`OJC@.
a. Access Manager zu& )#JC@ .
8:
dLv! %CKOY.
.&! Xa A
gD b] N WN; gkOB L[ gN B GP
b. h&& )#JC@ .
c. Tivoli Access Manager sec_master O#& TBOm .N ; ) #JC@ .
8:
d.
4. mI`!- Tivoli Access Manager for WebLogic; 8: X& OAi
AMWLSConfigure -action unconfig mI; gkO JC@. AMWLSConfigure
-action unconfig mI! g kR IG ! kQ Z< Q ; k: 63 d Lv G N O
B :mI | % |6 ;& |6OJC@ .
L}: Y= V&N 8:Gn V @ OY .
v :gD b] N WN; gkOB L[ gN B GP ;
v 47 dLv G : WebLogic -v! ^p. 9\! _}T;
g kZ! gD b] N W N; kX N uGz ; ' GQ L xB Z x! W<:OAm C
5OB fl, Y= @y ^Cv! %C I v V@OY.
d Lv! s JeM T 2 % CKOY.
8: X&
dLv! %CKOY.
WebSEALNNM ^Cv & gN BR v x@OY .
g kZ! G&N N uI v V B f l! 5 % AW L J G Servlet ! W<:R G Q L
x8GN L/Q fl ! _} R v V@OY.
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
46
b ; Nu ; gkR ' L /Q @ y ! _}R f l, 'G ^Cv! FQ N u < N gW
! kQARA.! gkZ ! T %CKOY. L B b; BEA WebLogic Server [ ?
L g gk Z ! w" GB WebSEAL ; kX d L v! W<:OB f l %CKOY.
WebLogic -v! ^p. 9\! _}T
.&!: java.lang.OutofMemory 9\! _}_@OY .
3 m: YvG Access Manager for WebLogic Server <G; G` _ N fl , BEA
WebLogic Server! | x#L N7R v V@OY .
Xa%: startWebLogic :)3.!- JVM(Java Virtual Machine) ! kQ V k | )
b IG; C.JC @ . 9 & i i , Y=z0@OY.
%JAVA_HOME%\bin\java -ms64m -mx128m -xms200m -xx:MaxPermSize=128m
n C.ILG 86, #:. C: [! - G ` _N ^p. }_ A N<:G v W BEA
WebLogic ServerG v |! {% G e | )b! kX- B BEA &0 .-& | 6O
JC @. nC.ILG /f G X g | )b& G0 O Ai n C.ILG ; W:. X _ U
OY.
&Qg W
1. Tivoli Access Manager for WebLogic: x/ Wl 8 :x (Wl ;G Wl ); v
xOv J@OY.
2. Tivoli Access Manager for WebLogic : Y_ Tivoli Access Manager 5^N
; vxO v8 " 5 ^ N! kQ sec_master g kZB sec_master )_ U OY. o ,
" Tivoli Access Manager 5^N! kQ L gk ZL'; /fOb 'Q IG
L v g &xG v J@OY.
3. BEA WebLogic Server 8.1!-B Wl L' ! ″ -″ .Z! vxG v J 8 GN W
l L'8 N any-other kE anyother& gkOJC @.
4. Active Directory! kX Tivoli Access Manager for WebLogic; 8:R ',
AdminGroupProp=Administrators 3$; Y% 3 $8N /fX_ U OY. L B
Active Directory! administrators WlLLL 8gO GN 8:L GPO b '
.TOY. Tivoli Access Manager for WebLogic ; 8:Om Tivoli Access
Manager for WebLogic |'& [:Ob |! ]eC L& v`X_ UOY .
5. Tivoli Access Manager for WebLogic \V; gkO )*R W policy& [:
R 'B C# & Q g W L vxG v J@OY. policy GB * R !B g k Z GB W
l ; _!R v x@OY . * R z policy g L !B ″OR″ 8 g k R v V8 g,
″AND″B vxG v J@ OY.
& 5 e |. B:) 47
6. Tivoli Access ManagerB b;{8N N C# ?H gk Z GQ $8& 3C U O
Y . PdPerm.properties G appsvr-credcache-life /: ; ;EO) L C#*
; 8:R v V@OY.
7. WebLogic Server Console Extension! kQ Tivoli Access Manager Plug-in for
Web Servers GB WebSEAL!- L[ gN BL v xGv J@OY . W/* N
M]!- W <:OB g kZB O]{8N WebLogic -v \ V ; g kR v x8
GN LB + .&! G v J@OY.
KAx .&! W.&Xa f}
1. Active Directory gkZ 9v:..& gkO ) 3!Oi Nu n C. IL G; h
!R ' .&! _} R v V@OY. L .&! : Administrator Wl W C:[
gkZ ! kXOeZ eH *R J N ! GQ M TOY. Active Directory !-
Administrator Wl W C:[ gkZB g| $ GH M L G N &ER v x@O
Y . Li @y& &EO m N u nC.I L G!CY% 8HL h !G5O O A i,
certificate.war % nC.I LG G h! p:)3 M& m}O) Xg JN ; &
EO m G& Administrator Wl W C:[ gkZ ! Xg OB J N; _ !OJC
@.
2. BEA WebLogic Server v| 8.1 !B Tivoli Access Manager for WebLogic L
\ V!- policy ;E; v `R v V5O ck O v JB . &! LV @OY . L .
&!G BEA WebLogic Server /f d;(CR) x#B CR125113 T OY. BEA
WebLogic Server 8.1 -q: Q! - L .&!L $$I 'nv \V; gkQ
policy ;E: vxG v J @OY .
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
48
& 6 e &E vCgW
Le!-B IBM Tivoli Access Manager for WebLogic Server& &EO B f} !
kX 3m U OY.
Y=}GvCgW; Oa O JC@.
v :Solaris!- &E ;
v 50 dLv G : Windows!- &E;
v 50 dLv G : AIX!- &E;
v 51 dLv G : HP-UX!- &E;
Solaris!- &E
Tivoli Access Manager for WebLogicG &E& x `Ob |! Tivoli Access Manager
| '& h&Om Tivoli Access Manager for WebLogic ; 8: X& _ Bv . N OJ
C@. Li B :)G v`! k Q Z<Q ;k : 45 d Lv G :Tivoli Access Manager
|' h&; W 46 dLv G : Tivoli Access Manager for WebLogic 8: X&;&
| 6OJC@.
Solaris!- Tivoli Access Manager for WebLogic; &EOAi pkgrm; gkOJ
C @. Y= v C gW; Oa O JC @.
1. rootNNWNOJC@.
2. Tivoli Access Manager for WebLogic; &EOAi Y = mI ;TBOJC@.
# pkgrm PDWLS
1 CQ P 0 vG & E& .NOB A R A . ! %CKOY. y& TB O JC@.
3. &E AN<: ?H :)3. ! super gkZ GQ 8N G`I M ; K.B fm!
% CKOY. y& TB O JC@.
DOL &EI ' " DOL sB ^Cv! * -KOY. postremove : )3 .! G`
H D, RA.~n P0v! &E GzYB sB ^Cv! % C KOY. pkgrm /?.<
! >aKOY.
Tivoli Access Manager for WebLogic P0v! &EGz@OY .
IBM Tivoli Access Manager b; g| 3! RA.~n (Tivoli Access Manager b
; 18S /f, Tivoli Access Manager b ; JRE(Java Runtime Environment) W
1 C{ Tivoli Access Manager nC.I L G 3_ 6)& & E OAi IBM Tivoli Access
Manager
b; 3! H; -
& |6OJC@.
© Copyright IBM Corp. 2003 49
Windows!- &E
Tivoli Access Manager for WebLogicG &E& x `Ob |! Tivoli Access Manager
| '& h&Om Tivoli Access Manager for WebLogic ; 8: X& _ Bv . N OJ
C@. Li B :)G v`! k Q Z<Q ;k : 45 d Lv G :Tivoli Access Manager
|' h&; W 46 dLv G : Tivoli Access Manager for WebLogic 8: X&;&
| 6OJC@.
Windows ANW % _! /&E FL\ NMd L:& gkO ) Tivoli Access Manager
for WebLogic DO; &EOJC@ . Y= vCgW ; OaOJC @ .
1. |.Z GQ LVB Windows gkZNNWNOJC@.
2. ANW % _!/& E FL\ ; N x )#JC@ .
3. Access Manager for WebLogic Application Server& 1COJC@ .
4. /f/& E& )#JC@ .
5. .N; )#JC@ .
Tivoli Access Manager for WebLogic DOL &EKOY .
/ v8v|. Oa k- s Z ! %CKOY.
AIX!- &E
Tivoli Access Manager for WebLogicL &EGz@OY .
IBM Tivoli Access Manager b; g| 3! RA.~n (Tivoli Access Manager b
; 18S /f, Tivoli Access Manager b ; JRE(Java Runtime Environment) W
1 C{ Tivoli Access Manager nC.I L G 3_ 6)& & E OAi IBM Tivoli Access
Manager
Tivoli Access Manager for WebLogicG &E& x `Ob |! Tivoli Access Manager
| '& h&Om Tivoli Access Manager for WebLogic ; 8: X& _ Bv . N OJ
C@. Li B :)G v`! k Q Z<Q ;k : 45 d Lv G :Tivoli Access Manager
|' h&; W 46 dLv G : Tivoli Access Manager for WebLogic 8: X&;&
| 6OJC@.
AIX P0v! kQ Tivoli Access Manager for WebLogic; &EOAi installp /
? .< & gkOJC @ .
IBM Tivoli Access Manager b; g| 3! RA.~n (Tivoli Access Manager b
; 18S /f, Tivoli Access Manager b ; JRE(Java Runtime Environment) W
1 C{ Tivoli Access Manager nC.I L G 3_ 6)& & E OAi IBM Tivoli Access
Manager
b; 3! H; -
b; 3! H; -
& |6OJC@.
& |6OJC@.
50
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
HP-UX!- &E
Tivoli Access Manager for WebLogicG &E& x `Ob |! Tivoli Access Manager
| '& h&Om Tivoli Access Manager for WebLogic ; 8: X& _ Bv . N OJ
C@. Li B :)G v`! k Q Z<Q ;k : 45 d Lv G :Tivoli Access Manager
|' h&; W 46 dLv G : Tivoli Access Manager for WebLogic 8: X&;&
|6OJC@.
swremove& gkO ) Tivoli Access Manager for WebLogic DO; &EOJC @.
Y = vCgW ; OaOJC @ .
1. rootNNWNOJC@.
2. Tivoli Access Manager for WebLogic; &EOAi Y = mI ;TBOJC@.
# swremove PDWLS
O C G sB ^Cv! % C KOY. P. \ h! Oa G z =; K.B sB ^ Cv
! %CKOY . swremove /?.<B Oep:)!- Tivoli Access Manager for
WebLogic DO; &EUOY .
&E! OaGi, swremove /? .< ! >aKOY.
L & HP-UX!- Tivoli Access Manager for WebLogic L &EGz@OY.
IBM Tivoli Access Manager b; g| 3! RA.~n (Tivoli Access Manager b
; 18S /f, Tivoli Access Manager b ; JRE(Java Runtime Environment) W
1 C{ Tivoli Access Manager nC.I L G 3_ 6)& & E OAi IBM Tivoli Access
Manager
b; 3! H; -
& |6OJC@.
& 6 e &E vCgW 51
52 IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
NO A. /: DO |6
Tivoli Access Manager for WebLogic; 8:Om | '& [:R ' TBGB % L
M B /: D O! ze K OY . Li /: D O: Tivoli Access Manager for WebLogic
G[?; /fOB % gkR v V@OY.
/ : D O: java_home/amwls/ wls_domain_name / wls_realm_name /! 8 g UOY.
)b- wls_domain_name : 8:H BEA WebLogic Server 5^NG L 'Lm
wls_realm_name :L 5^N ;! 8: H BEA WebLogic Server |'G L'T O
Y.
Y=z0L < 3 G /: D OL V@OY.
v amsspi.properties
BEA WebLogic Server! /$Q SSPI bI! kQ 8: / :L in V@OY .
v rbpf.properties
Tivoli Access Manager for WebLogic! kQ 8: / :L in V@ OY . 9&
in, 3C 3$ , *R /: W Tivoli Access Manager 8# @ j'. x# AWL
J L'TOY.
v amwlsjlog.properties
L D O! VB E3/v B v`H _ {/^Cv G g ; wTO ) Tivoli Access
Manager for WebLogic! kQ Nk W _ {; &nUOY. _ {; 0:-Oi Tivoli
Access Manager for WebLogicG :I!5b; Y v VYB !; Vv OJC @.
.&!G x N; G0OAm C5 R '8 _ {; 0:-R M ; G eUOY.
Y=}!-B " / : DO ! VB E3/v ! kX 3m U OY.
*** %CB Tivoli Access Manager for WebLogic ; 8:R ' T BGv JB /:
; *8 @OY. Li /: : 8: C#! b;* 8N 3$KOY. Li * ; b;* L
\G Y% * 8N 3$O Ai | '& [: W 8 :Ob | ! Xg .in DO ! VB /
: *; / fX_ UOY. config W create_realm 6! B .in DOG *; gkO )
ACL W Tivoli Access Manager 8# @ j '.& [:OGN 8 :OE* | ' & [
:Q D!B /f R v x@OY. Y=}!- ***N %CGv J: / :: 8 : LD
! 1T / fR v V @OY.
.in DO: pdwls_install_dir/etc!- # ; v V@OY.
amsspi.properties
L}!-B amsspi.properties DO ! VB /: ; * -Om 3m UOY.
© Copyright IBM Corp. 2003 53
com.tivoli.amwls.sspi.config.DeployerGroupProp***
b ;*: Deployers T OY. b ;{8N, BEA WebLogic Server!B W 3 G
|. WlLVB%, L /: : gk Z! Deployers |. Wl GL';
Deployers L\ G Y% L '8 N /fR v V 5O UOY.
com.tivoli.amwls.sspi.config.MonitorGroupProp***
b ;*: Monitors T OY. b ;{8N, BEA WebLogic Server!B W 3 G
|. WlLVB%, L /: : gk Z! Monitors |. Wl GL'; Monitors
L \ G Y% L '8 N /fR v V 5O UOY.
com.tivoli.amwls.sspi.config.OperatorGroupProp***
b;*: Operators TOY. b;{8N, BEA WebLogic Server!B W 3 G
WlLVB%, L /: : gk Z! Operators |. WlGL'; Operators
L\ G Y% L'8N /fR v V5O UOY.
com.tivoli.amwls.sspi.config.AdminGroupProp***
b ;*: Administrators T OY. b ;{8N, BEA WebLogic Server!B W
3G |. WlLVB%, L /: : gk Z! Administrator |. Wl GL
'; Administrators L\ G Y % L '8N /fR v V5O UOY. Windows
! LL AdministratorssB |. Wl;LL !v m Vb ' .! L /: ;
;EX_ OGN Active Directory& gk OB C:[! kX _ dQ /:T
OY.
com.tivoli.amwls.sspi.Authentication.GroupRegistryDelete
b ;*: true T OY . L /: : Tivoli Access Manager W lL h&I ' b
; p:d.!- W lL h& GBv ) N& a$UOY. LB pdadmin; g
kO ) Wl; h&R ' -registry C ! W& Qm tB Mz ?OUOY.
com.tivoli.amwls.sspi.Authentication.UserRegistryDelete
b ;*: true T OY. L B Tivoli Access Manager gk Z ! h&I ' b ;
p:d.!- g kZ! h& GBv )N& a $U OY. LB pdadmin; gk
O ) g k Z& h& R ' -registry C !W& Qm tB Mz ?O U OY.
com.tivoli.amwls.sspi.Authentication.ssoEnabled
b ;*: false T OY. BEA WebLogic Server ! kQ Tivoli Access Manager
Plug-in for Web Servers GB WebSEAL!- L[ gN B; g k !I /g
k R!I8N 3$U OY .
com.tivoli.amwls.sspi.Authentication.ssoTrustId
L [ gN B ; v`O b 'X WebSEAL GB Tivoli Access Manager Plug-in
for Web ServersM EZ ,|; .3OB % g kGB g kZ
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
54
com.tivoli.amwls.sspi.Authentication.ssoPasswdExpiry
b;*: 120( P)TOY . L /: : SSO EZ IDGNuL 3CGB C#(P )
; v$ UOY . L C# L OaGi, SSO gkZBY= x SSO C5 C Tivoli
Access Manager ! kX NuK OY .
com.tivoli.amwls.sspi.RoleMapper.EnableWebProgRolecheck
b ;*: true T OY . L /: :% AN W %D *R !K; g k !I G B g
k R!IO T UOY. L /: : |.Z! % nC.I LG ! kQANW %
D 8H; x v V5O UOY.
com.tivoli.amwls.sspi.RoleMapper.EnableEjbProgRolecheck
b ;*: true T OY. L /: : EJB AN W %D *R !K; g k !I G B
gk R!IO T UOY. L /: : |.Z! EJB ! kQANW %D 8H;
x v V5O UOY.
com.tivoli.amwls.sspi.Authentication.GroupDNPrefix
LDAPG fl , b;*: cn=TOY . L /: : \V . e8NNM W l ;[
:R ' |.Z ! "Nn& / f R v V5O UOY.
com.tivoli.amwls.sspi.Authentication.UserDNPrefix
LDAPG fl, b; * : cn=T OY . L /: : \V . e8NNM gk Z& [
:R ' |.Z ! "Nn& / f R v V5O UOY.
rbpf.properties
L}!-B rbpf.properties DO ! VB /: ; * -Om 3m UOY.
com.tivoli.pd.as.rbpf.ProductName
b;*: PDWLS TOY. Tivoli Access Manager @ j'. W ACL;[:
R ' V. W 3m! - L / :; gk UOY.
com.tivoli.pd.as.rbpf.RoleContainerName***
b ;*: Roles T OY. 8 : D, L / :: Roles/$WLS_Domain_Name
/$WLS_Realm_Name8N /fK OY. )b- WLS_Domain_Name: 8:H
BEA WebLogic Server 5^NG L'Lm, WLS_Realm_Name: 8:H BEA
WebLogic Server |'G L'TOY .
com.tivoli.pd.as.rbpf.ResourceContainerName***
b ;*: Resources T OY. 8 : D, L / :: Resources/
$WLS_Domain_Name /$WLS_Realm_Name8N /fKOY. )b-
WLS_Domain_Name: 8:H BEA WebLogic Server 5^ NG L'Lm,
WLS_Realm_Name: 8:H BEA WebLogic Server | 'G L'TOY.
NO A. /: DO |6 55
com.tivoli.pd.as.rbpf.PosRoot***
b ;*: WebAppServer T OY . L /:: Tivoli Access Manager for
WebLogic! VB pg *R W Z x! kQ @j'. x#G}k g.T O
Y .
com.tivoli.pd.as.rbpf.ProductId***
b ;*: WLS T OY. L /: : PosRoot *z a UO) pg * R W Zx
! kQ @j'. x#G g .& |:UOY.
com.tivoli.pd.as.rbpf.AMActionGroup***
b ;*: WebAppServer T OY . L /: : Tivoli Access Manager for
WebLogic W<: a$L ! KR 6!& ze OB % gk G B 6! WlG b
; L'T OY.
com.tivoli.pd.as.rbpf.AMAction***
b ;*: #b(invoke)! kQ i T OY . L 6!B Tivoli Access Manager for
WebLogicL W<: a$ ; v`R ' !KGg , AMActionGroup! _!KO
Y .
com.tivoli.pd.as.cache.EnableDynamicRoleCaching
b ;*: true T OY. L /: : ? { *R 3L ; gk !I G B gk R !
IOT U OY. pg 8k *R , o , |. *R L \G *R; 3C OA i ?{
* R 3C& g k UOY. `$ W N $ * R 8: x ; 3CUOY.
com.tivoli.pd.as.cache.DynamicRoleCache
b ;*: com.tivoli.pd.as.cache.DynamicRoleCacheImpl T OY . L /: : ?
{ *R 3L ; v`O B % gk G B ,!: TOY . Jd Q fl , gk ZG ?
{ * R 3 C& 8 vR v V @ OY . L B com.tivoli.pd.as.cache.
IDynamicRoleCache NMd L :& 8vO) v `R v V @OY.
com.tivoli.pd.as.cache.DynamicRoleCache.NumBuckets
b;*: 20 TOY. L /: : ? { *R 3C Wq ;zeOB % gk G B
b; XC WL m!- g kX_ OB v6G v& v$ UOY.
com.tivoli.pd.as.cache.DynamicRoleCache.MaxUsers
b ;*: 100000 T OY. L /: : 3C! V B pg v6! k Q Q W q v
TOY. L } Z& NumBucketsN *) i "30 v6G
OY.
com.tivoli.pd.as.cache.DynamicRoleCache.RoleLifetime
b;*: 20 TOY. L /: : `$ W N $ ?{ *R 3C a $L 3C! 2
F VB C#(J ) ; v$UOY.
com.tivoli.pd.as.cache.DynamicRoleCache.PrincipalLifeTime
b ;*: 10 T OY . L /: : A0C^(gk Z ) G Q $8! Tivoli Access
Manager for WebLogic 3C! zeGB C# (P ); v$UOY .
Vk
)b!a$K
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
56
PdPerm.properties * appsvr-credcache-lifeB GQ $8 ! PDJRTE! 3
C GB C #; a $QYB !; Vv O JC @. Tivoli Access Manager for
WebLogic: PDJRTE!- pg GQ $8 & .8U OY . {s- L * L
appsvr-credcache-life 8Y {; fl, LB Tivoli Access Manager for
WebLogicL PDJRTE!- 3CH GQ $8& Kv R ' cD a}OY .
com.tivoli.pd.as.cache.EnableStaticRoleCaching
b;*: true TOY. L /: : $ { *R 3L ; gk !I G B gk R!
IOT U OY. ${ `R 3C B |. *R ! kQ `$ W N $ * R 8:x
; 3COB % gk KOY. L 3CB Wq L 8aGv JB M ; &\OmB
?{ *R 3C M ?OUOY. LB L/Q * R! k Q 8:x L /f Gv J
8GN |. *R G :I ; 31UOY.
com.tivoli.pd.as.cache.StaticRoleCache
b;*: com.tivoli.pd.as.cache.StaticRoleCacheImpl TOY . L /: : $ { *
R 3L; v `OB % gk G B ,!:T OY. Jd Q fl, g kZG $ { *
R 3C& 8 vR v V@OY. LB com.tivoli.pd.as.cache.
IStaticRoleCache NMd L :& 8vO) v `R v V @OY.
com.tivoli.pd.as.cache.StaticRoleCache.Roles
b ;*: Admin, Operator, Monitor, Deployer T OY. L /: : 0%N 8
PH |. *R qO; 8/UOY. L qO! VB *R 8: x : ? { *R
3C8YB ${ *R 3C! _!KOY. b8 p g *R 8: x: ? { *R
3C! 3CKOY.
com.tivoli.pd.as.cache.EnableObjectCaching
b;*: true TOY. L /: : @ j'. 3L; gk !I G B gk R!I
O T U OY . L @j'. 3CB . e S: ; w TQ pg Tivoli Access
Manager @j'.& 3COB % g kK OY . L& gkO ) n2 BEA
WebLogic Server Zx! kX n2 *R L W<: N)GBv 3 LR v V
8 g, {s- " Z xd;! kX Tivoli Access Manager Authorization
Server& 68X_ OB Jd:; }+ R v V@OY .
com.tivoli.pd.as.cache.ObjectCache
b;*: com.tivoli.pd.as.cache.ObjectCacheImpl TOY. L /: : @ j'.
3 L; v`O B % gk G B ,! :TOY . Jd Q fl , gk ZG @j'. 3
C& 8vR v V @OY . LB com.tivoli.pd.as.cache.IObjectCache NMd L
:& 8vO) v `R v V @OY.
com.tivoli.pd.as.cache.ObjectCache.NumBuckets
b ;*: 20 T OY. L /: : b ; XC WL m !@j'. 3C Wq;ze
OB % gk G B v6G v& v$ UOY.
NO A. /: DO |6 57
com.tivoli.pd.as.cache.ObjectCache.MaxResources
b ;*: 10000 T OY. L /: : 3C! V B pg v6! k Q Q W q v
& v$UOY. L } Z & NumBucketsN *) i " v6G Vk )b !a
$KOY.
com.tivoli.pd.as.cache.ObjectCache.ResourceLifeTime
b ;*: 20 T OY . L /: : @ j '. 3C!- @ j '.! 8 8GB C#( P )
; v$UOY.
com.tivoli.pd.as.rbpf.UncheckedRoles
b;*: Unchecked, AmasUnckeched, Anonymous TOY. L /: : 0%N
8PH J2EE 1C k R *R qO; v$ UOY . * - H *R _ !- BEA
WebLogic Server Zx! kQ W<:! N )Gv J : *R LVB fl, p
g gkZB n2 8k *RL 7N GzBv! |h xLL! kQ W<:&
N )^@OY. g k Z M Wl:Li *R ! _! I v x@OY. L i *R:
p g gkZ(N u G v J: gk Z wT)!T / $ Zx! kQ W<: & N)
OB ?2{N f} ; %C UOY. Tivoli Access Manager for WebLogic 8
:LL <)Gv J: *R; )/ b; BEA WebLogic Server Z x! _
!R ' Anonymous * R : W s L qO! 2F V n_ U OY. L /: :
8 : |! 3 $RJdB xv8 O \ 3$H D !B /fOv JF_ U OY .
com.tivoli.pd.as.rbpf.ExcludedRoles
b;*: Excluded, AmasExcluded TOY. L /: : 0%N 8PH J2EE &
\*R qO; v$ UOY. {s- , Li * R _ Zx! 7NH * RLVB
fl, g kZB n2 8k *RL 7NGzBv ! |hxLL! kQ W<:
! N)Gv J@OY. L i J2EE & \*R: pg gk Z! k X /$ Zx
! kQ W<:& EN O B ?2{N f} ; %C U OY. L /: : 8: | !
3$RJdB xv8 O \ 3$H D !B /fOv JF_ U OY.
com.tivoli.pd.as.rbpf.GrantUnprotectedAccess
b ;*: true T OY. L /: : 8 #Gv JB d; H Zx, o , n0Q * R
5 N) Gv J: @j '.! kX W<:& N ) GB ENR MN v& v$
UOY.
com.tivoli.pd.as.rbpf.CopyParentRole***
b ;*: false T OY. | .ZB L /: ; gkO ) 8 Y /$ 9 'G *R( 9
: nC.ILG 9' G * R );[:R ' s' 9'! $ GH * R 8 :x(9
: [Nz *R ); 9gX_ OBv ) N& v$R v V@OY . Tivoli Access
Manager!- L / :: [Nz 9' ! 7NH ACLG pg 8:x ; nC.
I LG 9' G @j'. ! 7NH ACLN 9 gOB [ w ; wTUOY. L /
:: |. Z!T u *R ;[:R ' * R 8 :x! s SG 3d ;{kR v
VB b I ; &xUOY. O] {8N L /: :
PropogateChileRole z ?OQ * 8N 3$Gn_ UOY.
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
58
com.tivoli.pd.as.rbpf.PropagateChildRole***
b;*: false TOY. |.ZB L /: ; gkO ) s ' 9 '! $GH *R
8:x(9: [Nz *R) ! [:H /fgW L O ' *R( 9: nC.ILG 9
'G *R)!5 [ :GBv ) N & v$ R v V@OY . o , userA & [Nz *
R RoleA! _! R ' userA& GQ n C.ILG 9' G RoleA! _! UO
Y . L8T Oi * R 8:x ; ;ER ' CopyParentRole ; bsC0m u
* F! *R 8: x sS;{kUOY . O] {8 N L /: : CopyParentRole
z ?OQ *8N 3$Gn_ UOY.
com.tivoli.pd.as.rbpf.UseEntitlements
b;*: false TOY. L /: : n2 *R ! n2 Zx! kQ W<: ! N)
G zBv! |Q $ 8& v } O B % Tivoli Access Manager Authorization
ServerGN8L2U . -q:& gkX_ OBv ) N& %C UOY . b ;* :
false LGN, VR Tivoli Access Manager -q: v & 3 $O) Tivoli Access
Manager for WebLogic; G` C3 v V@OY . W/* , L /: : Tivoli
Access Manager Policy Server! kX \O GP v!; !vGN W:. /
f !-B falseN8 3 $Gn_ UOY. N8 L 2U . -q:B GQ ; N @ j
'. 3L! bJO ) N@ u t: 9' !-v`UOY. {s- , ANvG /
f !- L * : Ws trueN 3$Gn_ U OY.
com.tivoli.pd.as.rbpf.EntitlementsUser
b;+: Tivoli Access Manager for WebLogic remote-acl-user TOY. L
/ ::N8L2U . -q:& gkO )@ j'. Kv; v`OB % g kG
B gkZ& 8 /U OY. N8 L2U . -q: B Tivoli Access Manager 8
# @j'. x#G g kZ d; @j'.! -v |. O] ‘s’ GQ ; N )
^RBv .NU OY. config & v`O B ? H romote-acl-user B iv-admin W
l! _!G m L GQ L N )KOY. L g kZ& /fO ) g kZ d; @j
'.& ;ER v V v8, L ugkZ! Tivoli Access Manager 8# @j
'. x# G Resources AW LJ! kX ‘s’ G Q ; N)^RB v .NX_ U
OY.
com.tivoli.pd.as.rbpf.IgnorePasswordPolicyOnUserCreate
b;*: false TOY. |.ZB L /: ; gkO ) BEA WebLogic Server
\V; kX u Tivoli Access Manager gk Z& [:R ' O# policy&
+CR v V @OY.
com.tivoli.pd.as.rbpf.DeleteBaseRoleRecursive
b;*: true TOY. L /: : s ' *R ; h&R ' pg O ' *R ; h
&R MN v )N& %C UOY.
N O A. /: D O |6 59
amwlsjlog.properties
amwlsjlog.properties D O: %X JLog /: D OT OY. L D O: Tivoli Access
Manager for WebLogicz PDJRTE!- ^Cv |^ W _ {; &nOB % g kK
OY .
amwlsjlog.properties DO! wTH /:L kNP L % G q {! {UOv J 8
GN L}!-B pg / :; * -Ov J@OY. L D O !- ^Cv |^ W _ {;
gk GB gk R!IO T R v V@OY.
amwlsjlog.properties DOG Wq : h~ 86 {T OY. )/ 8: d R ! k Q N
k; Qx! QE* \ O 8:dR! kX N k; S v V@OY.
N k; Q A i, \xw N k; gk !IO T O A B 8:d R ! isLogging / :; _
!OJC@. F! ! * -H Wq: Tivoli Access Manager for WebLogic L vx O
B _{ W ^Cv | ^ 8:d R T OY . Li *- H /: _ O* G B pN! k X
_{/^Cv |^ ; gk !IO T R v V@OY. Y =: " 8:d R ! v`OB [
w; #+O T 3mUOY.
8:d R3m
AmasRBPFTraceLogger Tivoli Access Manager for WebLogicG ;N
AmasCacheTraceLogger pg Tivoli Access Manager for WebLogic 3C
AMSSPICfgTraceLogger Tivoli Access Manager for WebLogicG config
AMSSPIAuthzTraceLogger Tivoli Access Manager for WebLogicG GQ &
AMSSPIAuthnTraceLogger Tivoli Access Manager for WebLogicGNu&
AMSSPIRoleMapperTraceLogger Tivoli Access Manager for WebLogicG *R J
AMSSPIResourceManagerTrace
Logger
AmasCacheMessageLogger Tivoli Access Manager for WebLogicG ;N 6
AmasRBPFMessageLogger pg Tivoli Access Manager for WebLogic 3C
AMSSPICfgMessageLogger Tivoli Access Manager for WebLogicG config
AMSSPIAuthzMessageLogger Tivoli Access Manager for WebLogicG GQ &
_{
6 [! kQ _ {
! kQ 6[
6[! kQ _ {(9: *R [:)
xZ! kQ _ {
xZ! kQ _ {
N &xZ! k Q _{
Tivoli Access Manager for WebLogic ;GZx
|.Z! kQ _ {
^Cv |^
[ ! kQ ^Cv | ^
! kQ ^Cv | ^
6[! kQ ^C v |^(9: *R [:)
x Z! kQ ^Cv | ^
60 IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
8:d R3m
AMSSPIAuthnMessageLogger Tivoli Access Manager for WebLogicGNu&
xZ! kQ ^Cv |^
AMSSPIRoleMapperMessage
Logger
AMSSPIResourceManager
MessageLogger
Tivoli Access Manager for WebLogic G *R J
N &xZ! k Q ^Cv |^
Tivoli Access Manager for WebLogic ;GZx
| .Z! kQ ^ Cv |^
'G " 8:d RB baseGroup traceLogger W baseGroup messageLogger& .
eUOY. {s- , /: D O!- Li G /: : Y = 9& M /gOT *8 3OY.
baseGroup.AMSSPIAuthnMessageLogger.isLogging=true
'G 9&B Tivoli Access Manager for WebLogic GN u&xZ =G! kQ ^C
v |^ ; gk !IO T UOY. G Q &xZ& &\Q pg 8: dR ! kQ _{;
gk !IO T OAi Y= s N; _ !OJC @.
baseGroup.TraceLogger.isLogging=true
baseGroup.AMSSPIAuthzMessageLogger.isLogging=false
o , pg Y % _{ 8:d R B\xw b; N W AN W %! - true *; s S UOY.
L! ]X, G Q NW ANW % : true * ; falseN cD9OY.
N O A. /: D O |6 61
62 IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
NO B. m I |% |6
© Copyright IBM Corp. 2003 63
AMWLSConfigure -action config
Tivoli Access Manager for WebLogic Server& 8:UOY .
8.
AMWLSConfigure -action config -domain_admin domain_admin
-domain_admin_pwd domain_admin_password -remote_acl_user remote_acl_user
-sec_master_pwd sec_master_pwd -pdmgrd_host pdmgrd_host -pdacld_host
pdacld_host [-deploy_extension {true|false}] [-wls_server_url wls_server_url ]
[-am_domain am_domain ] [-pdmgrd_port pdmgrd_port ] [-pdacld_port pdacld_port ]
[-amwls_home amwls_home ] [-verbose {true|false}]
E3/v
-am_domain am_domain
Tivoli Access Manager 5^NG L '; v$UOY . b; 5^N: Default TO
Y.
-amwls_home amwls_home
Tivoli Access Manager for WebLogic Server 3! p:d.! kQ f N & v
$UOY.
-deploy_extension {true|false}
trueN 3$R fl Tivoli Access Manager Web Logic Server v| 5.1 \V
.e; h!UOY. b;* : trueT OY.
-domain_admin domain_admin
WebLogic 5^N | .Z & v$UOY .
-domain_admin_pwd domain_admin_password
WebLogic 5^N | .Z O# & v$UOY .
-pdacld_host pdacld_host
Tivoli Access Manager Authorization Server #:. L'; v$UOY .
-pdacld_port pdacld_port
Tivoli Access Manager Authorization Server w. x#& v$UOY . b; w
. x#B 7136T OY.
-pdmgrd_host pdmgrd_host
Tivoli Access Manager Policy Server #:. L'; v$UOY .
-pdmgrd_port pdmgrd_port
Tivoli Access Manager Policy Server w. x#& v$UOY . b; w. x#
B 7135T OY.
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
64
!k:
-remote_acl_user remote_acl_user
Authorization Serverk8N [:GB Tivoli Access Manager A0C^ (gkZ )
; v$UOY.
-sec_master_pwd sec_master_pwd
Tivoli Access Manager |. gkZ O# (8k sec_master )& v$UOY .
-verbose {true|false}
trueN 3$R fl Z <Q b B; gk !IO T UOY . b;*: falseTOY .
-wls_server_url wls_server_url
N C WebLogic -v! kQ URL; v$ U OY . b;*: t3://localhost:7001
TOY.
L mI : Y =z0: b; 3! p:d.! '!UOY.
v UNIX:
/opt/pdwls/sbin/
v Windows C:[G fl :
.O Ze
C:\Program Files\Tivoli\pdwls\sbin\
b;* L\ G Y% 3! p:d .& 1CR ', L/?.<B 3! p:d. F !G
sbin p:d.(9 : install_dir \sbin\)! '!UOY .
Y=z0: >a sB Ze! . OI v V@OY.
0 mIL O aGz@OY.
1 mI! GP_ @OY.
m I! GPO i @y ^ Cv! % C KOY . .&!GZ<Q 3 m! kX -B IBM
Tivoli Access Manager Error Message Reference& |6OJC@.
NO B. m I |% |6 65
AMWLSConfigure -action unconfig
Tivoli Access Manager for WebLogic Server& 8: X& UOY .
8.
AMWLSConfigure -action unconfig -domain_admin_pwd domain_admin_pwd
-sec_master_pwd sec_master_pwd [-verbose {true|false}]
E3/v
-domain_admin_pwd domain_admin_pwd
Tivoli Access Manager for WebLogic Server 5^N | .Z O# & v$U OY .
-sec_master_pwd sec_master_pwd
Tivoli Access Manager |. gkZ O# (8k sec_master )& v$UOY .
-verbose {true|false}
trueN 3$R fl Z <Q b B; gk !IO T UOY . b;*: falseTOY .
!k:
L mI : Y =z0: b; 3! p:d.! '!UOY.
.O Ze
v UNIX:
/opt/pdwls/sbin/
v Windows C:[G fl :
C:\Program Files\Tivoli\pdwls\sbin\
b;* L\ G Y% 3! p:d .& 1CR ', L/?.<B 3! p:d. F !G
sbin p:d.(9 : install_dir \sbin\)! '!UOY .
Y=z0: >a sB Ze! . OI v V@OY.
0 mIL O aGz@OY.
1 mI! GP_ @OY.
m I! GPO i @y ^ Cv! % C KOY . .&!GZ<Q 3 m! kX -B IBM
Tivoli Access Manager Error Message Reference& |6OJC@.
66 IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
AMWLSConfigure -action create_realm
WebLogic -v ;! 8H |'& [ :UOY .
8.
AMWLSConfigure -action create_realm -realm_name realm_name
-domain_admin_pwd domain_admin_pwd -user_dn_suffix user_dn_suffix
-group_dn_suffix group_dn_suffix -admin_group admin_group [-user_dn_prefix
user_dn_prefix ] [-group_dn_prefix group_dn_prefix ] [-sso_enabled {true|false}]
[-sso_user sso_user ] [-sso_pwd sso_pwd ] [-verbose {true|false}]
E3/v
-admin_group admin_group
;N 8: k5 ! g kR Tivoli Access Manager Wl; v$UOY.
-domain_admin_pwd domain_admin_pwd
WebLogic 5^N | .Z O# & v$UOY .
-group_dn_prefix group_dn_prefix
Wl;[:R ' gk R 80 L'(DN) "Nn & v$ UOY.
-group_dn_suffix group_dn_suffix
Wl;[:R ' gk R 80 L'(DN) "Ln & v$ UOY.
-realm_name realm_name
[: _ N WLS | 'G L'; v$UOY.
-sso_enabled {true|false}
trueN 3$R fl L[ gN B 8 6 |.Z& gk !IO T UOY . b;*:
falseTOY.
-sso_pwd sso_pwd
L[ gN B gkZ(sso_user )G O#& v$UOY.
-sso_user sso_user
Tivoli Access ManagerM L[ gN B EZ ,|;[:Ob ' Q gkZ& v
$UOY.
-user_dn_prefix user_dn_prefix
gkZ& [:R ' gkR 80 L'(DN) "Nn & v$ UOY.
-user_dn_suffix user_dn_suffix
gkZ& [:R ' gkR 80 L'(DN) "Ln & v$ UOY.
-verbose {true|false}
true N 3$R fl Z < Q b B ; gk !IO T UOY . b;*: false T OY .
NO B. m I |% |6 67
!k:
.O Ze
L mI : Y =z0: b; 3! p:d.! '!UOY.
v UNIX:
/opt/pdwls/sbin/
v Windows C:[G fl :
C:\Program Files\Tivoli\pdwls\sbin\
b;* L\ G Y% 3! p:d .& 1CR ', L/?.<B 3! p:d. F !G
sbin p:d.(9 : install_dir \sbin\)! '!UOY .
Y=z0: >a sB Ze! . OI v V@OY.
0 mIL O aGz@OY.
1 mI! GP_ @OY.
m I! GPO i @y ^ Cv! % C KOY . .&!GZ<Q 3 m! kX -B IBM
Tivoli Access Manager Error Message Reference& |6OJC@.
68
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
AMWLSConfigure -action delete_realm
WebLogic -v! - 8H |'& h&UOY .
8.
AMWLSConfigure -action delete_realm -domain_admin_pwd domain_admin_pwd
[-registry_clean {true|false}] [-verbose {true|false}]
E3/v
-domain_admin_pwd domain_admin_pwd
WebLogic 5^N | .Z O# & v$UOY .
-registry_clean {true|false}
8 : _ [ :H gkZ W W l; &EUOY. b ;*: falseT OY.
-verbose {true|false}
true N 3$R fl Z < Q b B ; gk !IO T UOY. b; * : falseT OY.
!k:
L mI : Y =z0: b; 3! p:d.! '!UOY.
.O Ze
v UNIX:
/opt/pdwls/sbin/
v Windows C:[G fl :
C:\Program Files\Tivoli\pdwls\sbin\
b;* L\ G Y% 3! p:d .& 1CR ', L/?.<B 3! p:d. F !G
sbin p:d.(9 : install_dir \sbin\)! '!UOY .
Y=z0: >a sB Ze! . OI v V@OY.
0 mIL O aGz@OY.
1 mI! GP_ @OY.
m I! GPO i @y ^ Cv! % C KOY . .&!GZ<Q 3 m! kX -B IBM
Tivoli Access Manager Error Message Reference& |6OJC@.
NO B. m I |% |6 69
70 IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
NO C. VGgW
L $8B L9!- & xGB & 0 W -q:k 8 N [ :H M T OY. IBM : Y% 9
!!-B LZa! bzH &0, -q: GB bI; &xO v J ; v5 V@ OY. v
g gkR v V B &0 W -q:! k Q $8 B Q9 IBM cg Z !T . G OJC
@. L % !- IBM &0 , ANW % GB -q:& p^OB ML Xg IBM & 0, A
N W % GB -q:8; gkR v V YB M;GLOvB J@ OY . IBMG v {g
jG; 'XOv JB Q, bI s8N ?nQ & 0, A NW % GB -q:& kE gk
R v V@OY. W/* q IBM & 0 , A NW % GB -q:G nk! k Q r! W K
u: gk ZG % STOY.
IBM :L %!- Ygm V B /$ ; k! kX / c & 8/ O m V E * v g / c
bx _O v V@OY. L %; &xQY m X- / c! k Q s L>:nv N)OB
M : FUOY. s L >:! kQ G .gW : Y =8 N . G OJC@.
135-270
-o/0C -28 5 n ? 467-12, :N x &8 | t y
Q 9 FL.q .% VD8g
m487>M
| -x # : 080-023-8080
2YL. (DBCS) $8! |Q sL>: . GB Q9 IBM m487>M! .GO E*
Y= VRN -i . GOCb Yx OY
IBM World Trade Asia Corporation
Licensing
2-31 Roppongi 3-chome, Minato-ku
Tokyo 106, Japan
Y = \ t: vv}z sf O B 59L* b 8 9 ! !- B {kGv J@ OY . IBM:
8 NG G. q'X, s 0 : W /$ q { !G{ U:! k Q ,C{ 8u ; w TO )
(\ , L! QOv J = ) ,C{Lg m C{Lg n0Q >y G 8ux LL% ; “vs
B kN” &xU OY . ON 9!!- B /$ E!!- mC{ G B ,C{ 8u G i%
g W; c k O v J8GN, L g WL{kGv J; v 5 V@OY.
L $8!B bz {8N N$.Q ;k L* Nbs G @y! V; v V@OY. L $
8 B Vb{8N / fGg, / fH gW: VEG! k U K OY. IBM:L %!-3
mQ & 0 W(GB ) ANW %; g | kvx L p&g v 31 W(GB ) / f R v V@
OY .
© Copyright IBM Corp. 2003 71
L $8!- p^GB q IBM G% g L .B\v mGs & xH M 8N, n2 fD 8
Ng L i % g L.& K#Om Z OB M : FUOY. X g % g L.GZaB ;
IBM &0 Za GON! FOGN X g % g L. gk 8N NQ 'h : gk Z ;N
L (vX_ UOY.
IBM: MO G G.& 'XOv JB | ' ;!- {}OYm } " OB fD 8N MO
! & xQ $8& gk O E* hwR v V@OY.
(i) 63{8N [: H ANW %z b8 ANW % (; ANW % w T ) #G $8 3/ W
(ii) 3/H $8G s # Lk ; q {8N $8& xOB A N W% sL>: gk ZB
Y = VRN . G OJC@.
135-270
-o/0C -28 5 n ? 467-12, :N x &8 | t y
Q9 FL.q .% VD8g
m487>M
L/Q $8B Xg 6G(9& in , gk a vR n)! {s gkR v V@OY.
L $8! bzH s L>:! N)H ANW % W g k !IQ pg s L>:! VB
ZaB IBM L IBM b; h` , IBM ANW % s L>: h`(IPLA) GB LM ?n
Q h`! {s & x H M TOY.
; .-! wTH p g :I %LM B &QH /f! - jbH MTOY. { s - Y%
n5 /f !- rnx azB s gw Y& v V@OY. ON :I: 3_ 9' sB G
C: [!- x$Gz; v V8GN L /Q x$!! O ] {8 N g k Gm VB C: [
!-5?OOT *8 / M LsmB 8uR v x@ OY. GQ, ON :I : _$ ; k
X _xGz; v 5 V8GN G& azBY& v V@OY. L % G gk Z B X g
%LM& gk ZG /$ /f!- K uX_ UOY.
qIBM &0! | Q $ 8B X g &0G x^w<, x3 Za G BY% b8 |k R
:NNM r: M T OY. IBM !-B L / Q qIBM & 0 ; W :.Ov JR 8GN, L
i &0z|CH :IG $. :, #/ : GB b8 Ve! k X -B .ER v x@O
Y. q IBM &0G : I! kQ G.g W: X g &0G x^w<! . G OJC@.
IBML &COB f b GB G5! |Q n0 Q p^ 5 /0Q kvx L /fI v V
@OY.
L $8!B Os G qnO: n5!- g kG B Za W 8m-! kQ 9& ! in
V@OY. L 9& !B !IQ O.OT3d; 3mOb 'X 3 N, 8g , s% W &
0 GL'L gkI v V @OY. L i L ': p N !xG M L g G& bwGL'
W VRM /gOus5 L B |{8 N l, TOY.
IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
72
s%
L $8& RA.+ GN 8B fl! B g xz C/ p- ! %CG v J ; v5 V@O
Y.
Y= kn B L9 G B b8 9!!- g kG B IBM CorporationG s% G B nO
s %TOY.
AIX
DB2
IBM
IBM Nm
SecureWayTivoli
Tivoli Nm
Microsoft, Windows, Windows NT W Windows NmB L9 G B b8 9 !!-
g kGB Microsoft CorporationG s %TOY.
Java W pg Java b] nO s%M NmB L 9 GB b8 9!!- g kGB Sun
Microsystems,IncG s% GB nO s% TOY .
UNIXB L9 G B b8 9!!- g kG B Open GroupG nOs% TOY .
b 8 8g, &0 W -q: L': 8 gG s % GB -q: % TOY.
NO C. VGgW 73
74 IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
kn
!
!s #:.(virtual hosting). NM]! Q Ls G #:.N *
8*5O OB % -v G b I
3 Nk 0(private key). D;M 8H!-R/Z8L gkR v
xk 0
3Nk 0
5^N
(domain) |6
M k6
M k6
S::*
j
(rule) |6
V 8N 8:Gg, 0
VB 0.
x k 0(public key). C: [ 8H!- pg gwL g k R v
VB 0.
|. 5 ^N(management domain). Tivoli Access Manager
! Nu, GQ N) W W<: &n& 'X 8H policy& {k
OB b; 5^N. L 5^N: Policy Server! 8:I ' [
:KOY .
|. -v(management server). u LsgkOv J@OY .
Policy Server |6
|. -q:(administration service). Tivoli Access Manager
Z x |. Z nC.I L G!- |. d; ; v`Ob 'X gk
R v VB G Q API 18S C/WN. |. -q:B 8# @
j '... ;G /$ k e F!!@j'.& *-OB Mz
0L B:)& v`O b 'X pdadmin mI ; kX x ] d;
! @dU OY. m4 : GQ ADK& g kO ) L/Q -q:&
3_R v V@OY .
80 L'(DN: distinguished name). p:d. ;!- W q
; D0OB m /L'. 80 L ':
%N 8P UOY .
8 :(configuration). (1) $8 3. C: [G Oe~n W R
A.~n! 8:G n s# ,aGB fD. (2) C:[, -j C:
[ GB W.v )& 8:OB C: [ , pYL: W ANW %
GQ j(authorization rule).
|., \N GQ , GQ $8 v $ , N8L2 U. W PAC 6[N
MdL:! V@OY . m4 : GQ ADK& gk O) L/Q -
q:& 3_R v V @OY .
GQ $8 v $ -q:(credentials modification service).
Tivoli Access Manager GQ $8& v $ O b 'X gk R v
VB GQ API 18 S C/W N. m4 L \N !- 3_Q G Q
$ 8 v $ -q:B GQ $ 8 S: qO! _!O m L q O!
- &EOB 6[; v`O 5O &Q Gg, v$ !IQ M8N #
V GB S: i 88N & QKOY .
G Q $8(credentials). Nu 5 _ ! r :Z <Q $8N, gk
Z, Wl ,| W b8 8H |C ID S: ! kX 3m U OY .
G Q $8& gk O ) Yg Q -q:(9 : G Q, (g W 'S )&
v`R v V@OY .
G Q(authorization). (1) C: [ 8H!- C: [ z k EOE
* C: [; gkR v V 5O gk Z !T N )GB GQ. (2) @
j'., Zx GB b I ! kQ O |OE* &QH W<:& g
kZ !T N )OB AN<:
GQ(permission). 8# @ j'.(9: DO GB p:d. )! W
<:R v VBIB. @j'. ! Xg OB G Q v M GLB
ACL(Access Control List)!- $GK OY . ACL(Access Control
List) |6
[Nz gN B(GSO: Global Signon). gkZ! gkZL
' W O# & i#e % nC .ILG-v! &xR v V5O
OB 6k: V B L[ gN B Vg G. [Nz gN B : \O
N WN; kX gkZ! g k R G QLVB D;C Zx! W
< :R v VT X ]OY . L b> G Pj D;C /f ;! - )
/ C: [ W nC.ILG 8 N 8:H + T pG #MAs L n
! {UO T 8inx GSO & g kOi g kZB )/ g kZL
' W O# & | .Ov JF5KOY.
Signon) |6
L[ gN B
(SSO: Single
GQ -q: C/ WN(authorization service plug-in). GQ API
;!--q: NMd L :& .eOB [w ; v`O b 'X, J
b- C Tivoli Access Manager GQ API 18S ,sLp.
!- NeR v VB ? {8 NNe !IQ sLj/.(DLL G
B x/ s Lj/.). v g gk ! IQ -q: NMd L :! B
© Copyright IBM Corp. 2003 75
b; Nu(basic authentication). 8H BsNZx! W<:
R v VB G Q L N)Gb ! U-, g k Z ! CY% g k ZL
' W O# & TBX_ OB Nu ^Re
*
W.v) b] Nu(network-based authentication). gkZ
G IP(Internet Protocol) VR& YA 8 N @j'. W<:& &
nOB POP(Protected Object Policy). POP(Protect Object
Policy) |6
Y
Y_ dR N u(multi-factor authentication). gkZ! N 3
Ls GNu 9'; g kO ) N uO5 O - & G `O B
POP(Protected Object Policy). 9& in, 8# Z x! kQ W
< : &n! - gkZB g kZL'/O#M g k ZL'/d+ O
# ZeQYN NuX_ U OY. POP(Protected Object Policy)
|6
\h0 Nu(step-up authentication). g| 8:H Nu 9'
h ~ 86! G8 Og, ZxG policy <.! {s / $ 9'G
Nu ; -& G`O B POP(Protected Object Policy). \ h0 N
u POP & gkO i gkZ! V n x Zx! W<:Ob 'X )
/9 'GNu; gkO v JF5Gv8, gkZ! VRQ Z
x; 8#OB policy !- d8OB 9' !- NuX_ UOY .
L [ gN B(SSO: Single Signon). gkZ! Q x NW B
Oi ""G n C.ILG! 30 {8NNWBOv Jm5 )/
n C.ILG! W <:R v VB b I .
Global Signon) |6
5 ^NL'(domain name). NM] AN d ]:!- #:. C
:[GL'. 5 ^NL': P ..ZN 8PGB OC G O 'L
'8N 8:KOY . 9 & in, #:. C: [G O | Q 5 ^ N
L'(FQDN)L as400.rchland.vnet.ibm.comO fl, Y =: "
" 5 ^NL' TOY. as400.rchland.vnet.ibm.com,
vnet.ibm.com, ibm.com
5 ^N(domain). (1) xk -q:& x /Og 8k x kGB q
{8N bIO B gkZ, C:[ W Zx G m. Wl-. (2) %
LM 3. Zx L xk &n O! VB C: [ W.v ) NP .
5 ^NL'
p :d. :0 6(directory schema). p:d.! * 8 / v V
B CY% S: /| W @ j'. ,!:. S: /| W @ j'
. ,!:B S: * 8.(9& in , n2 S: L 8 gX _ O
B v, W.m p:d .! k X n2 S: L 8g R v V B v);
$GUOY .
(domain name) |6
[Nz gN B
(GSO:
pU(daemon). ,S GB Vb{8 N C: [ |'G b I( 9:
W.v) &n); v`O b 'X + N8N G`GB A NW % . O
N pU: Xg B:) & v`O b 'X Z ? 8N ..E G m, *
Sv p U: $b {8N [?UOY .
p vP -m(digital signature). e-commerce!- %LM \ '
! _!G E* %LM \ 'G O# |[ ! Xg OB %LMN, %
LM \ ' vE Z! \ 'G +a: W R:& . NOm '6 !
I:;NDR v VT UOY.
s
slCDO(routing file). ^Cv 8:; &nOB mI; w
TOB ASCII DO
1 8S(run time). C: [ ANW % ; G `O B C#. 1 8 S /
f: G` / fTOY .
9v:..(registry). gkZ, C: [ W RA. ~n ! kQ W
<: W 8 : $8& wTO B %LM ze R
j (rule). L%. -v! L %. # G |h (L %. s|)& N D
Om L! {s Z? @d ; G `R v V5O OB O* Ls
G m.mI.
6
6LW9 LG(migration). L| v| GB 1. :& YYb '
XANW %G u v | GB 1. :& 3!O B M
^8%L M(metadata). zeH%LMG /: ; 3mOB % L
M
Y
YNe(bind). ID& ANW % ;G Y % @j'. M |C~B
M. 9& in ,ID& *, VR GBY% IDM |C~ E* , |D
{N E3/v W G& E 3/vM,|~B M
8 H |.(security management). 6w G :x! _ d Q %
LM W nC.I LG G W<:& & nOb 'Q 6w G IB ;
v$OB |. T"
8 # vX(quality of protection). Nu, +a: W As L v
C 6G 6 U8N G0GB % L M 8H v X
8# @ j'. x# (protected object space). ACL W POP
& {kOb 'X gk O g gkZ W<: GQ N )! gkO
76 IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
B G& C:[ Zx G !s @j'. % C.
(protected object) W POP(Protect Object Policy) |6
8# @ j'.(protected object). ACL W POP & {kOb '
X gk Og gkZ W<: G Q N)! gk OB G& C:[
Z x G m. %C. POP(Protect Object Policy) W
'. x#
9 & ;(replica). Y% -vG p:d . g;; wTO B -v.
9& ;: :I G B @d C# ; bsC0m % LM +a: ; 8
eOb 'X -v& iw UOY .
(protected object space) |6
8# @ j'.
8# @ j
F
O#- (encryption). C: [ 8H!- x! %L M& O# X
6 AN<:8; gk O) < v V 5O -XQ | B N //O
B AN<:
O#(cipher). 0& gkO ) 8 k %L MN //(O # X6)G
b |!B P; v x5O O#-H%LM
W<: GQ(access permission). |< @j'. ! {kOB W
<: GQ
m9Le(blade). nC.ILG /$ -q: W 8 :d R & &
x OB 8:d R
qnO: N8 L2U .(business entitlement). Zx! |Q G
Q d;!- g k R v VB Z< Q 6G; 3m OB gkZ G
Q $8G 8f S:
g
gkZ 9v:..(user registry).
gkZ(user). Y% 3N, 6w , AN<: , pY L:, ANW % ,
ANd] GB C: [!- &x OB -q:& gk OB pg 3
N, 6w , AN<: , pY L:, ANW % , ANd] GB C:[
-q:(service). -v! -v `GB [w. -q: B % LM& 8
;E * ze Ob ' Q \x Q d;LE * (DO -v , HTTP
Server, |Z lm -vW NE -v !- ), u 9bQ [w (9 :
N b-v GB AN<: - v G -q:) O v V @OY .
S: qO(attribute list). GQ; a$ O b 'X gk O B .
e $8& wTO B 5)H qO. S: qO :
N 8:KOY .
:06(schema). %LM# L : 86& O | OT 3m O B mI
. <.N, %LM $ G pn N %v KOY . |h | % LM# L :
!- :06B W Lm, " W Lm G Je, J e M WLm # G |
h& $GUOY .
9v:..
(registry) |6
L'=*
V 8
W <: & n (access control). C: [ 8H!- GQLVB g
kZ8 L GQ L N )H fD8N C:[ Z x! W<:R v V
5O 8eOB A N<:.
*R v$ (role assignment). gkZ! Xg *R ! $GH @
j'.! |X {} Q W<: G Q; .B M33, g kZ !T *
R; v$ OB AN<:
*R 0:-(role activation). *R! W<: GQ;{kOB
AN<:
,a(connection). (1) %LMkE!- $8 |^ ;'Q bI
e! g L! 3$GB ,|. (2) TCP/IP !- EZR v VB %
LM :.2 |^ -q:& &xO B N 3 G ANd] n C.
ILG g LG fN. NM]!- ,a : Q C: [ G TCP nC
.ILG!- Y % C: [G TCP nC .ILG 8N . eUOY .
(3) C:[kE!- N C:[ gL GB C:[z pYL : g
L! % LM& |^R v VB 81
\ N GQ - q :(external authorization service). Tivoli
Access Manager GQ a$ < NG ONN nC.ILG GB /
f /$ GQ a $;'X gk R v VB G Q API 18S C
/WN. m4 : GQ ADK& gk O) L /Q -q:& 3_ R
v V@OY .
@ d D O (response file). ANW % !- d ; O B z.! B B
g |$ G H @ d <.& w TO g, Q x! O *? * ;T BO
BkE gkGB DO
EZ:VB g.(trusted root). SSL(Secure Sockets Layer)
!- CA(Certificate Authority)G x k 0 W ,|H 80 L
'
N u-(certificate). C: [ 8H!- x k 0 & Nu-R/Z
G ID! Y NeO) Nu-R/Z& NuR v V5O OB p
v P .-. N u -B CA(Certificate Authority) ! - _^UOY .
N u(authentication). (1) C: [ 8H!- g k Z ID GB g
kZG @j'. W<: GQ; .NOB M. (2) C:[ 8H !
- ^Cv! / f GB U sGv JR B v .NOB M. (3) C
:[ 8H!- $ 8 C:[ GB 8# Zx G gk Z& .NO
kn 77
b 'X gk O B A N<:.
(authentication) W
u
N8 L2U . -q:(entitlement service). A0C^ GB 6G
< .G \N R :NNM N8 L2U .&.OOb ' X gk R v
VB GQ API 18 S C/W N. N8 L2U .B 8k /$ f
D 8N Z x |. Z nC.I L G!-R qOE**_! GQA
N<:!- gkOb ' XA0C^G GQ $8! _! R n C
.ILG /$ % LM TOY . m4 : GQ ADK & gkO ) L
/ Q -q:& 3_ R v V@OY .
N 8 L 2U .(entitlement). \N-H 8 H policy $ 8 & wT
OB %LM 86. G Q!B /$ n C.ILG 8N L XR v V
B fD8N | D -H b I G B policy %LM! V @ OY .
NM] AN d]:(Internet suite of protocols). NM]!-
gkOb ' X 3_Gn IETF(Internet Engineering Task Force)
& kX RFC(Requests for Comment)N x3 H AN d] <.
Y_ dR N u ,W.v) b] N
\h0 Nu
(authentication) |6
m 0(cookie). -v! ,sLp. C: [ ! ze O m D S<G
!- W <:OB $8. m0 B -v! ,sLp. ! kQ /$$
8& boR v VT UOY .
)b 6$ !I(scalability). Zx! W<:OB gk Z v G u
!! @dOb 'Q W. v) C: [ bI
0 %L M#L: D O(key database file).
6
0 5(key ring). C: [ 8H!- x k 0 , 3Nk 0 , EZ:
VB g. W Nu ; wTO B D O
0 V(key pair). C: [ 8H!- x k 0 W 3Nk 0 . O
#- ! 0 V; g k R ', [EZB x k 0& g k O ) ^C
v & O#- Om, vEZB 3 Nk 0 & gkO) ^ C v & O#
X6 UOY . -m! 0 V; g k R ', -mZB 3 Nk 0 & g
kO ) ^Cv % C & O#- Om, vEZB x k 0& g kO )
-m .N; ' X ^Cv % C & O# X6 UOY .
0 5
(key ring) |
Z
Z? 3!(silent installation). ^Cv & \V! 8;v J v 8
k E NW DO! ^ C vM@y& ze OB 3!. G Q Z? 3
!!-B %LM TB ;'X @d D O; gk R v V@OY .
@d D O
Z x@j'.(resource object). G& W.v) Z x (9 : -q
:, DO W ANW % )G % C
Z< nO(self-registration). gkZ! J dQ %LM& TB R
v Vm|.ZG |) xL nO H Tivoli Access Manager g
kZ! I v VB AN<:
"Ln(suffix). NC N 8/OB p :d. h~ 86!- G '
Wq; D0 OB 80 L'. LDAP(Lightweight Directory
Access Protocol)!- g kGB s k{L'v$ fD8N NX,
L "LnB p:d. h~ 8 6 ;G Y%pg Wq! {k K
OY . p:d. -v!B N C N 8/ G B p :d. h~ 86 "
"; D0OB )/ 3G "Ln ! V; v V@OY .
6 ! (action). ACL(Access Control List) GQ S: .
ACL(Access Control List) |6
(response file) |6
0 5
0 DO(key file).
0(key). C: [ 8H!- %L M O#- W O# X6;'X
O #- K m.r!- g k OB OC G b#.
xk 0
key) W
(public key) |6
(key ring) |6
3Nk 0
(private
8
d+(token). (1) YE. kE A!- :WL GLSCN |[ E
< &n O! V=; % C O b ' X %LM :W L G #!,S
{8N |^G B GQ b#. ""G % LM :W LG!B E< &
& nOb ' X d+ ; 9f O m gk R b8! V@OY . d+ :
|[ GQ ; K.B /$ ^Cv GB q.POTOY . (2) Y
E . kE A (LAN)!- | [ E <M T2 pYL: # ! |^G
B q. Cv :. d+ ! %LM! _ ! H f l, L d+ : A9
SL K OY.
D
wP(portal). /$ gkZG W<: GQ; b]8N, /$ g
kZ! g k !IQ %Zx(9: 5) , ;k GB -q:)G g
kZ $ G qO ; ? {8N [:OB k U % g L.
+
AWLJ @j'.(container object). @j'. x# ; 05G
bI region! 8:OB 86{ v$
z 5(polling). %LM G| [ )N& a$Ob 'X %LM # L
:& $b{8 N 6gOB AN< :
78 IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
O
#:.(host). W.v)(9: NM ] GB SNA W.v))!,
aGn V m W W.v)! W<:OB v! ; & xOB C: [.
G Q #:.B / f! { s W.v)G _S }_ -H & n& &
xR v5 V@OY . # :.B ,s Lp. -v, GB ?C! ,
s Lp.M -v QY! I v V @OY .
A
ACL. ACL(Access Control List) |6
ACL(Access Control List). C: [ 8H!- @ j'.! W
< :R v VB pg V<M X g W < : GQ; D 0OB @ j
'.M,|GB qO. 9 & in, ACL: D O! W<:R v
V B gk Z & D0Om L D O ! kX g k Z !!vm VB
W<: GQ; D0OB DOz ,|H qO T OY.
B
BA.
b; Nu
(basic authentication) |6
C
CA. CA(Certificate Authority) |6
CA(Certificate Authority). N u- & _ ^O B b|.
CA(Certificate Authority)B Nu-R/ZG IDM W R /Z
!T g k GQL N )H -q: Nu, u Nu - _^, b8 N
u - g_^, gkR G Q L u L s xB g k ZG N u - s
b n; v`UOY .
CGI(Common Cateway Interface). HTTP d;; kX %
-v! - nC.IL G8N $8& |^O B :)3.& $ GO
b 'Q N M] %X. ]k G fl5 6y !v T OY . CGI :)
3.B :) 3. pn (9 : Perl)N [:H CGI ANW %TOY .
D
DN.
80 L'
(distinguished name:DN) |6
E
EAS.
\N GQ - q:
(External Authorization Service) |6
F
FTP(File Transfer Protocol). NM] AN d]:!- C: [
L * #:. g L ! k. % L M D O; | [Ob 'X TCP W
Telnet -q:& gkOB n C .IL G h~ ANd]
G
GSO. GSO(Global Signon) |6
H
HTTP. HTTP(Hypertext Transfer Protocol) |6
HTTP(Hypertext Transfer Protocol). NM] AN d]:!
- OL[X:. . -& | [Om %C Ob ' X gk OB AN
d]
CDAS. CDAS(Cross Domain Authentication Service) |6
CDAS(Cross Domain Authentication Service). b;
WebSEAL Nu ^?O r ; , Tivoli Access Manager ID&
WebSEAL! .OOB g kZ $ G AN<: N k< ! I OT
O B x/ s L j/.^?Or; & xO B WebSEAL -q: .
WebSEAL |6
CDMF. CDMF(Cross Domain Mapping Framework) |6
CDMF(Cross Domain Mapping Framework). 3_Z !
WebSEA e-Community SSO bI; gkR ' g k Z ID J
N W gkZ S: 3.& gkZ ! BT $G R v VT OB
ANW !V NMd L:
CGI. CGI(Common Cateway Interface) |6
I
IP. IP(Internet Protocol) |6
IPC. IPC(Interprocess Communication) |6
IPC(Interprocess Communication). (1) ANW %L - N %
LM& [v EOm 0? ; ?b-OB AN<: <6wn, E #
W ;N ^Cv %! AN< : # k EG xk f}TOY . (2)
AN<:! ?O Q C:[ ; GB W.v )& k X Y% AN
< :M -N kER v V5O OB n5 <& ^? O r
IP(Internet Protocol). NM] AN d ]:!- % L M& W.
v) GB s# ,aH W. v)& kX s l.Om s' AN
d] h~ z G& W.v ) gLG _h *R; OB , a xB
ANd]
kn 79
J
junction. AP.#e WebSEAL -v M i #e % n C.I
LG-v #G HTTP GB HTTPS , a. WebSEAL : junction
; gkO ) i #e -v kE 8# -q:& &xO T UOY .
L
LDAP. LDAP(Lightweight Directory Access Protocol) |6
LDAP(Lightweight Directory Access Protocol). (a) X.500
p(; vxOB p:d .! W<:R v VB GQ ; &xOb
'X TCP/IP & gk Om, (b) u 9 bQ X.500 DAP(Directory
Access Protocol)GZxd8gW; 87 OB 3f ANd].
LDAP& gkOB n C .ILG(p:d . gk !I nC .IL
G Lsm5 T) : 3 N GB -q:! kQ $ 8 (9 : |Z lm
VR, xk 0 GB -q: / $ 8: E3/ v) Kv;'X x
k %L M ze RN p : d.& gkR v V@OY. LDAP B x
! RFC 1777 ! v$ Gn V z@OY. LDAP v| 3 : RFC
2251 ! v$Gn V8g , IETF B hSX- _ ! %X b I ! k
X ,8 Om V@OY. IETF !- $ G Q ON LDAP k %X :
06B RFC 2256!- < v V@ OY.
LTPA. LTPA(Lightweight Third Party Authentication) |6
LTPA(Lightweight Third Party Authentication). NM] 5
^N ;! SX VB % -v <. & ED L[ gN B ; ck
OB Nu A9Sv)
!5 g kR v V@OY . m4 : G Q ADK& g kO) L/
Q -q:& 3_ R v V@OY . PAC(Privilege Attribute
Certificate) |6
PAC(Privilege Attribute Certificate). A0C^(gkZ )GN
uz GQ N) S: W A0C^(gkZ )G bI; wTO B p
vP .-
policy. |. Zx! {kGB j <.
Policy Server. 8H 5^N!- Y % -v! kQ '! $ 8
& /v8vOB Tivoli Access Manager -v
POP. POP(Protect Object Policy) |6
POP(Protect Object Policy). 8# @ j'.! W<:R v
V5O ACL policy ! ck OB 6 [! _! 6 G ;{kOB 8
H policy /| . POP 6G;{kOB M:Zx |.ZG %
STOY. ACL(Access Control List) ,
object) W
8# @ j'. x#
(protected object space) |6
8# @ j'.
(protected
R
RSA O#- C: [ (RSA encryption). O#- W Nu! g
kOB x k 0 O#- C: [. 1977 b Ron Rivest, Adi Shamir
W Leonard Adleman! GX mHH O#- C: [ TOY . N
3G + Rv *v;NvPXO B nArG $5 ! {s, C:
[ 8HL ^s} OY.
S
M
SSL. SSL(Secure Sockets Layer) |6
MPA(Multiplexing Proxy Agent). )/ ,sLp. W<:
& 6}OB T L .~ L . L T L .~ L B #$ ,s L p.!
WAP& gkO ) 8H 5 ^N! W<:R f l , WAP(Wireless
Access Protocol) TL.~ Ls m5 UOY . TL.~ LB x!
-v! \ONuH $N; 3 $ Om, pg ,sLp. d; W
@d ;L$N ; kX MN5UOY .
SSL(Secure Sockets Layer). kE AsLv C & &xOB 8
H ANd]. SSL: ,sL p ./-v n C.ILG L 5;, #7
W ^Cv '6 & fvOb ' X 8in x fD8N k ER v
VT UOY . SSL : Netscape Communications Corp.M RSA
Data Security, Inc.!- 3__@OY .
SSO. SSO(Single Signon) |6
P
PAC. PAC(Privilege Attribute Certificate) |6.
PAC -q: (privilege attribute certificate service). g|!
G0H |DG PAC & Tivoli Access Manager G Q $ 8N, G
B W ] k N //O B GQ API 18S ,sLp. C / W N.
L/Q -q:B 8H 5^ NG Y% 8:x! T |[Ob 'X
Tivoli Access Manager GQ $8& P0! OE* $D R fl
80 IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-
U
URI. URI(Uniform Resource Identifier) |6
URI(Uniform Resource Identifier). Zx L'(p:d . W
D OL'), Zx '!(p:d . W DOL'LVB C: [) W
Zx W<: f} ANd]( 9: HTTP) ; wTO ) NM] G A
Y w& D0Ob ' X gkGB .Z -. URIG Q 9NB m/
Q Zx '! v$ Z, o URLLV@OY .
URL. URL(Uniform Resource Locator) |6
URL(Uniform Resource Locator). C:[ GB N M]z0
: W.v)(9: NM])!- $8 Zx ; %C OB . Z Cv :.
L .Z Cv :!B (a) $8 Zx! W<:Ob 'X gk OB
A Nd]G ``H L 'z (b) $8 Z x; #b ' XA Nd]
!- g kOB $8! V@ OY. 9& in, NM] A X:. !
- Li : YgQ $8 Zx! W <:Ob ' X gk OB AN
d ]G ``H L 'T OY(9 : http, ftp, gopher, telnet W news).
IBM ( dLv G URL: http://www.ibm.comTOY .
W
WebSEAL. Tivoli Access Manager m9Le . WebSEAL:
8# @ j'. x# ! 8H policy & {kOB m: I G Y_ :
9e % -v TOY . WebSEAL : L[ g N B V gG; &x
Om i#e % n C.ILG-v Zx ; 8H policy! kU
R v V@OY .
WPM. WPM(Web Portal Manager) |6
WPM(Web Portal Manager). 8H 5^N!- Tivoli Access
Manager b; W WebSEAL 8H policy& | .Ob ' X g
k OB % b] W ! H n C .ILG. pdadmin m I ` NMd
L:! kQ kH 8N, L GUIB x]|.Z W<: & !IO
T O m , | .Z ! 'S H gkZ 5 ^N; [ :O) L 5 ^N
! 'S |.Z & v$ R v V T UOY .
kn 81
82 IBM Tivoli Access Manager for e-business: BEA WebLogic Server kU H;-