This section provides instructions for configuring Access Manager resources, including:
Instructions for using Access Manager as the Web Access Control for Identity Manager
Follow these steps when setting up the IBM Tivoli Access Manager resource for use with Identity Manager:
Install the IBM Tivoli Access Manager Java Runtime Component on the Identity Manager server.
Set your PATH variable to include the path to the JVM for your application server.
Remove the following jar files from the InstallDir\idm\WEB-INF\lib directory (depending on your application server, these files may have been removed during the Identity Manager product installation):
The number that follows security.provider in each line specifies the order in which Java consults security provider classes and should be unique. The sequence numbers may vary in your environment. If you already have multiple security providers in the java.security file, insert the new security providers in the order given above and renumber any existing security providers. Do not remove the existing security providers and do not duplicate any providers.
Add the VM parameter to the application server:
If necessary, you can add multiple packages by delimiting with a | (pipe symbol). For example:
-Djava.protocol.handler.pkgs=sun.net.www.protocol| \ com.ibm.net.ssl. internal.www.protocol
Make sure the IBM Tivoli Access Manager Authorization Server is configured and running.
Run theSvrSslCfg command:
java com.tivoli.pd.jcfg.SvrSslCfg -action config \ -admin_id sec_master -admin_pwd secpw \ -appsvr_id PDPermissionjapp -host amazn.myco.com \ -mod local -port 999 -policysvr ampolicy.myco.com:7135:1 \ -authzsvr amazn.myco.com:7136:1 -cfg_file c:/am/configfile \ -key_file c:/am/keystore -cfg_action create
The am directory must already exist. Successful completion creates these files in the c:\am directory:
The following procedure describes the general configuration steps to use Tivoli Access Manager as the Web Access Control for Identity Manager. Some of the following steps require detailed knowledge of the Tivoli Access Manager software.
Install and configure IBM Tivoli Access Manager Java Runtime Component on the Identity Manager server.
Configure the JDK Security Settings on the Identity Manager server.
Create the Access Manager SSL Config files on the Identity Manager server.
Create a Junction in Access Manager for the Identity Manager URLs. Refer to the Tivoli Access Manager product documentation for more details.
The following example pdadmin command illustrates how to create a junction:
pdadmin server task WebSealServer create -t Connection / -p Port -h Server -c ListOfCredentials -r -i JunctionName
Configure the Identity Manager Base HREF property for the WebSeal Proxy Server.
Set up the Access Manager resource adapter.
Load the Access Manager users into Identity Manager.
Configure pass-through authentication for Access Manager in Identity Manager.
When a user attempts to access the Identity Manager URLs through Access Manager, the user’s identity is passed in the HTTP header to Identity Manager. Identity Manager then uses that identity to verify the user exists in Access Manager and in Identity Manager. If the user is trying to access the Identity Manager Administrator interface, Identity Manager checks the Identity Manager Security configuration for the user to make sure they have Identity Manager administrative rights. End users are also verified against Access Manager, and whether they have a Identity Manager account.