Sun Java logo     �W�@��      �ؿ�      �d�      �U�@��     

Sun logo
Sun Java System Access Manager 6 2005Q1 �޲z��n 

�� 2 ��
�b SSL �Ҧ����t�m Access Manager

�ϥΨ㦳²��{�Ҫ��w���M���h (SSL) �i�H�O�Ҿ�K�ʩM��Ƨ���ʡC�Y�n�b SSL �Ҧ����ҥ� Access Manager�A�q�`�n�G

  1. �H�w�� Web �e���t�m Access Manager
  2. �N Access Manager �t�m��w���� Directory Server

�H�U�U�`�y�z�o�ǨB�J�G


�ϥΦw�� Sun Java System Web Server �t�m Access Manager

�Y�n�ϥ� Sun Java System Web Server �b SSL �Ҧ����t�m Access Manager�A�аѾ\�H�U�B�J�G

  1. �b Access Manager �D���x���A���ܪA�Ȱt�m�Ҳըÿ�� [���x] �A�ȡC�b [��A���M��] �ݩʤ��A���� http:// ��w�A�M��[�J https:// ��w�C��@�U [�x�s]�C

  2. �Ƶ�   

    �аȥ���@�U [�x�s]�C�_�h�A��M�z���i�H�~����U�����B�J�A��z�Ұ����Ҧ��t�m�ܧ󧡷|�򥢡A�åB�L�k�H�޲z���n�J�H�ץ������D�C


�B�J 2 ���B�J 25 �y�z Sun Java System Web Server�C

  1. �n�J Web Server �D���x�C�w�]�s���� 58888�C
  2. ��� Access Manager ���W��檺 Web Server ��ҡA�M���@�U [�޲z]�C
  3. �t�η|��ܧ��㦡��A����t�m�w�ܧ�C��@�U [�T�w]�C

  4. ��@�U�e���k�W���� [�M��] ��s�C
  5. ��@�U [�M�γ]�w]�C
  6. Web Server �|�۰ʭ��s�ҰʡC��@�U [�T�w] �H�~��C

  7. ������ Web Server ��ҡC
  8. ��@�U [�w��] ���ҡC
  9. ��@�U [�إ߸�Ʈw]�C
  10. ��J�s����Ʈw�K�X�ë�@�U [�T�w]�C
  11. �нT�O�O�U��Ʈw�K�X�A�H�Ƶy��ϥΡC

  12. �إ߾��Ҹ�Ʈw��A��@�U [�ШD����]�C
  13. �b�e�����Ѫ���줤��J��ơC
  14. �z�b [��ȹ����K�X] ��줤����J�P�z�b�B�J 9 ������J�ۦP�C�b��m��줤�A�ݭn����g�X�ԲӦ�m�C�Y�g�� (�p CA) �L�ġC�����w�q�Ҧ����C�b [�@�ΦW��] ��줤�A���ѱz Web Server ���D��W�١C

  15. �������A�z�N�ݨ�P�H�U�T������T���G
  16. --BEGIN CERTIFICATE REQUEST---

    afajsdllwqeroisdaoi234rlkqwelkasjlasnvdknbslajowijalsdkjfalsdflasdf

    alsfjawoeirjoi2ejowdnlkswnvnwofijwoeijfwiepwerfoiqeroijeprwpfrwl

    --END CERTIFICATE REQUEST--

  17. �ƻs�o�Ǥ�r�ô���A�H�ШD���ҡC
  18. �нT�O�z��o�F Root CA ���ҡC

  19. �z�N������]�t���Ҫ����Ҧ^3�A�p�G
  20. --BEGIN CERTIFICATE---

    afajsdllwqeroisdaoi234rlkqwelkasjlasnvdknbslajowijalsdkjfalsdflasdf

    alsfjawoeirjoi2ejowdnlkswnvnwofijwoeijfwiepwerfoiqeroijeprwpfrwl

    --END CERTIFICATE---

  21. �N�o�Ǥ�r�ƻs��ŶKï�A���x�s�b�ɮפ��C
  22. ���� Web Server �D���x�ë�@�U [�w�˾���]�C
  23. ��@�U�� Server �����ҡC
  24. �b [��ȹ��ɮױK�X] ��줤��J���Ҹ�Ʈw�K�X�C
  25. �b���Ѫ���r��줤�K�W���ҡA�ή֨����s�æb��r����J�ɮצW�١C��@�U [����]�C
  26. �s��N��ܸӾ��ҡA�ô��ѥ[�J���Ҫ���s�C

  27. ��@�U [�w�˾���]�C
  28. ��@�U [�i�H����ұ��v��쪺����]�C
  29. �H�B�J 16 ���B�J 21 ���ҭz���ۦP�覡�w�� Root CA ���ҡC
  30. ��Ӿ��Ҧw�˧�����A��@�U Web Server �D���x���� [�ߦn�]�w] ���ҡC
  31. �p�G�n�b���P���s����W�ҥ� SSL�A�п�� [�[�J��ť�M���r]�C�M���� [�s�谻ť�M���r]�C
  32. �N�w�����A�q [����] �ܧ� [�ҥ�]�A�M���@�U [�T�w] �����ܧ�C

�B�J 26 ���B�J 28 ���� Access Manager�C

  1. �}�� AMConfig.properties �ɮסC�̹w�]�A���ɮצ�� etc/opt/SUNWam/config�C
  2. �� https:// ��N�X�{���Ҧ� http:// ��w�AWeb Server ��ҥؿ���~�CAMConfig.properties ���]��w�F�o�@�I�A��O��@�P�C
  3. �x�s AMConfig.properties �ɮסC
  4. �b Web Server �D���x���A��@�U�U�� Web ��A����Ҥ� Access Manager �� [�}��/��] ��s�C
  5. Web Server �|�b [�Ұ�/����] ��������ܤ@�Ӥ�r���C

  6. �b��r��줤��J���Ҹ�Ʈw�K�X�ÿ�� [�Ұ�]�C


�ϥΦw�� Sun Java System Application Server �t�m Access Manager

�N Access Manager �]�w���b�w�ҥ� SSL ��Sun Java System Application Server �W���A�L�{�(�B�J�C����A�N Application Server ��һP�w�˪� Access Manager �w�����X�b�@�_�A�M��t�m Access Manager �����C

�ϥ� SSL �]�w Application Server 6.2

�n�w�����X Application Server ��ҡG

  1. �z�L�b�z���s���J�H�U��}�A�H�޲z���n�J Sun Java System Application Server �D���x�G
  2. http://fullservername:port

    �w�]�s���� 4848�C

  3. ��J�z�b�w�ˮɿ�J���ϥΪ̦W�٩M�K�X�C
  4. ���z�b��W�w�� (�αN�n�w��) Access Manager �� Application Server ��ҡC�k�ج[�|��ܰt�m�w�ܧ�C
  5. ��@�U [�M���ܧ�]�C
  6. ��@�U [���s�Ұ�]�CApplication Server �|�۰ʭ��s�ҰʡC
  7. �b���ج[���A��@�U [�w��]�C
  8. ��@�U [�޲z��Ʈw] ���ҡC
  9. ��@�U [�إ߸�Ʈw] (�p�G�����)�C
  10. ��J�s����Ʈw�K�X�ýT�{�A�M���@�U [�T�w] ��s�C�нT�O�O�U��Ʈw�K�X�A�H�Ƶy��ϥΡC
  11. �إ߾��Ҹ�Ʈw��A��@�U [���Һ޲z] ���ҡC
  12. ��@�U [�ШD] �s�� (�p�G�����)�C
  13. �����ҿ�J�H�U�ШD���
    1. �p�G�Ӿ��Ҭ��s���ҩΧ�s�����ҡA�h���C�\�h���ҷ|�b�@�q�S�w�ɶ���L�aA�Y�Ǿ��ұ��v��� (CA) �|�۰ʵ��z�ǰe���s�q���C
    2. ��w�z�n������ҽШD���覡�C
    3. �p�G�Ʊ� CA �����q�l�l��T���Φ����ШD�A�Ю֨� [CA �q�l�l��] �ÿ�J CA ���q�l�l���}�C�p�� CA �M��A�Ы�@�U [�i�ξ��ұ��v���M��]�C

      �p�G�z�q�ϥ� Sun Java System Certificate Server ������ CA �ШD���ҡA�h�Ы�@�U [CA URL] �ÿ�J Certificate Server �� URL�C�� URL 3�ӫ�V�B�z���ҽШD�����Ҧ�A���{���C

    4. ��J�z��ȹ��ɮת��K�X (�z�b�B�J 9 ����w���K�X)�C
    5. ��J�H�U�ѧO��T�G
    6. [�@�ΦW��]�C��A��������W�١A�]�t�s���𸹡C

      [�ШD�̦W��]�C�ШD�̪��W�١C

      [�q�ܸ��X]�C�ШD�̪��q�ܸ��X�C

      [�@�ΦW��]�C�N�b��W�w�˼Ʀ���Ҫ� Sun Java System Application Server ������W�١C

      [�q�l�l���}]�C�޲z��q�l�l���}�C

      [��´�W��]�C�z��´���W�١C���ұ��v���i��|�n�D�b���ݩʤ���J���Ҧ��D��W�٧��ݩ��U��Ӳ�´�����C

      [��´�椸�W��]�C��´���$�B����Ψ�L�B�@����W�١C

      [�a�ϦW�� (����)]�C�z�Ҧb�����Ϋ��?�W�١C

      [�{���W��]�C�p�G�z����´�'O�b���Υ[���j�A�������´�Ҧb�{�ά٪��W�١C�Ф��Y�g�C

      [��a/�a�ϥN�X]�C�N��z��a/�a�Ϫ���Ӧr�*� ISO �N�X�C�Ҧp�A��ꪺ�N�X�� US�C

  14. ��@�U [�T�w] ��s�C�e���W�N�|��ܰT���A�Ҧp�G
  15. --BEGIN NEW CERTIFICATE REQUEST---

    afajsdllwqeroisdaoi234rlkqwelkasjlasnvdknbslajowijalsdkjfalsdfla

    alsfjawoeirjoi2ejowdnlkswnvnwofijwoeijfwiepwerfoiqeroijeprwpfrwl

    --END NEW CERTIFICATE REQUEST--

  16. �N�Ҧ��o�Ǥ�r�ƻs��@���ɮרë�@�U [�T�w]�C�нT�w�z��o�F Root CA ���ҡC
  17. ���@�� CA�A�è̴`���v����W��������A�H��o�Ʀ���ҡC�z�i�H�q CMS�BVerisign �� Entrust.net ��o����
  18. �q���ұ��v��챵����Ʀ���ҫ�A�z�i�H�N��r�ƻs��ŶKï�A�αN���x�s���ɮפ��C
  19. ���� Sun Java System Application Server �D���x�ë�@�U [�w��] �s���C
  20. ��� [����A��������]�C
  21. �b [��ȹ��ɮױK�X] ��줤��J���Ҹ�Ʈw�K�X�C(�P�b�B�J 9 ����J���K�X�ۦP)�C
  22. �b���Ѫ���r���B [�T��] ��r (�a�����Y) ���K�W���ҡA�Φb���ɮפ�r��� [�T��] ����J�ɮצW�١C����3������s�C
  23. ��@�U [�T�w] ��s�C�s��|��ܾ��ҡA�ô��ѥ[�J���Ҫ���s�C
  24. ��@�U [�[�J��A������]�C
  25. �H�B�J 10 ���B�J 22 ���ҭz���ۦP�覡�w�� Root CA ���ҡC��O�A�b�B�J 18 ���A�п�� [�i�H����ұ��v��쪺����]�C
  26. �w�˧���Ӿ��ҫ�A�i�}���ج[���� [HTTP ��A��] �`�I
  27. ��� [HTTP ��A��] �U�� [HTTP ��ť�{��]�C
  28. ��� http-listener-1�C�s��|��ܮM���r��T�C
  29. �N http-listener-1 �ϥΪ��s���𪺭ȱq�w�� Application Server �ɿ�J�����ܧ󬰧�A�?�� (�p 443)�C
  30. ��� [�ҥ� SSL/TLS]�C
  31. ��� [���ҧO�W]�C
  32. ��w�^�Ǧ�A���C�Ӧ�A��3�ӻP�B�J 12 ����w���@�ΦW�٬۲šC
  33. ��@�U [�x�s]�C
  34. ���z�n�b��W�w�� Sun Java System Access Manager �n�骺 Application Server ��ҡC�k�ج[�|��ܰt�m�w�ܧ�C
  35. ��@�U [�M���ܧ�]�C
  36. ��@�U [���s�Ұ�]�CApplication Server �|�۰ʭ��s�ҰʡC

�ϥ� SSL �]�w Application Server 8.1

�n�w�����X Application Server ��ҡG

  1. �T�{�w���� Application Server ��ҡC
  2. �ϥ� asadmin>change-master-password ��O���ܧ�O���K�X�C
  3. ���� Application Server �D���x�A�ÿ�� [�t�m]>[HTTP �A��]>[HTTP ��ť�{��]�C
  4. ��@�U�z�n�ҥΪ���ť�{���A�M��b���T���椤��� Security:Enabled�C
  5. �ˬd�O�_�w�� certutil�C
    1. ���� /usr/sfw/bin�C
    2. �Y�D�A�h�q�U�C�ؿ�w�� SUNWtlsu �M�˳n��G
    3. /share/builds/integration/security/SECURITY_3_9_3_03B4/packages/~platform~

    4. Shell ����ܼơALD_LIBRARY_PATH
    5. LD_LIBRARY_PATH has to have /usr/lib/mps/secv1

  6. �ϥ� certutil ���ˬd certdb ���w�˪����ҡG
    1. ���� /var/opt/SUNWappserver/domains/domain1/config
    2. certutil -L -d
    3. �z�N�ݨ�U�C��X�G
    4. /var/opt/SUNWappserver/domains/domain1/config/% certutil -L -d

      Application Server 8.1 �b�w�ˮɶ��w�˦ۧ�ñ�p����A������ (�O�W�As1as)�A�ñN��Ω� ssl �ҥΪ��s���� 4848,8181�C

  7. ���;��ҽШD�C�n��檺�y�k�O�G
  8. certutil -R -s subj -o cert-request-file [-d certdir] [-P dbprefix] [-p phone] [-a]

    �Ҧp�G

    certutil -R -s "CN=test.company1.com, O=company1.com, C=US" -o cert.req -d . -a

  9. �ϥΥH�U��O�A�q CA �^����ҡG
  10. certutil -A -n cert-name -t trustargs [-d certdir] [-P dbprefix] [-a] [-i input]

  11. �N��A�������x�s���ɮסC
  12. �ϥΤU�C��O�y�k�w�˫H�� CA ���ҡG
  13. certutil -A -n cert-name -t trustargs [-d certdir] [-P dbprefix] [-a] [-i input]

    �N�i�H�� CA �����x�s���ɮפ��A�Ҧp cacert.txt�C

  14. �C�X certdb �H�T�O�w�˦��\�C�п�J�H�U��O�G
  15. /var/opt/SUNWappserver/domains/domain1/config/% certutil -L -d

  16. ���� Application Server �޲z�D���x�A�ÿ�� HTTP ��ť�{���C
  17. �b [�@��]�w] �U�A�ϥηs��A�����Ұt�m HTTP ��ť�{���C

  18. ���s�Ұ� Application Server�C

�b SSL �Ҧ����t�m Access Manager

�Y�n�b SSL �Ҧ����t�m Access Manager�G

  1. �b Access Manager �D���x���A���ܪA�Ȱt�m�Ҳըÿ�� [���x] �A�ȡC�b [��A���M��] �ݩʤ��A�[�J�ϥ� HTTPS ��w���ۦP�� URL �M�@�Ӥw�ҥ� SSL ���s���𸹡C��@�U [�x�s]�C

  2. �Ƶ�   

    �p�G Access Manager ��@��ҥ��b��ť��ӳs���� (�@�� HTTP�A�@�� HTTPS)�A�B�z�չϥH��� Cookie �s�� Access Manager�AAccess Manager �N�S���^3�C�o�ëD�䴩���t�m�C


  3. �q�H�U�w�]��m�}�� AMConfig.properties �ɮסG
  4. /etc/opt/SUNWam/config.

  5. �� https://��N�X�{���Ҧ� http://��w�A�ñN�s�����ܧ󬰤w�ҥ� SSL ���s���𸹡C
  6. �x�s AMConfig.properties �ɮסC
  7. ���s�Ұ� Application Server�C


�ϥΦw�� BEA WebLogic Server �t�m AMSDK

�b SSL ���ϥ� AMSDK �i��t�m���e�A������w�� BEA WebLogic Server �ðt�m�� Web �e���C�p�ݦw�˻���A�аѾ\ BEA WebLogic ��A�����C�Y�n�� Access Manager �N WebLogic �t�m�� Web �e���A�аѾ\�� 1 ���uAccess Manager 2005Q1 �t�m�{���� �v�C

�Y�n�t�m�w�� WebLogic ��ҡG

  1. �ϥΧֳt�}�l�\���ӫإߺ��
  2. ���� WebLogic �w�˥ؿ�ò��;��ҽШD�C
  3. �ϥ� vetri_csr.txt CSR �N��A�����ҮM�Φ� CA
  4. �N�֭㪺�����x�s���r�ɤ��C�Ҧp�Aapprovedcert.txt�C
  5. �ϥΥH�U��O�A��J cacerts ���� Root CA�G
  6. cd jdk141_03/jre/lib/security/

    jdk141_03/jre/bin/keytool -keystore cacerts -keyalg RSA -import -trustcacerts -alias "Greenday CA" -storepass changeit -file /opt/bea81/cacert.txt

  7. �ϥΥH�U��O�Ӹ�J��A�����ҡG
  8. jdk141_03/jre/bin/keytool -import -keystore keystore -keyalg RSA -import -trustcacerts -file approvedcert.txt -alias "mykey"

  9. �ϥαz���ϥΪ̦W�٩M�K�X�n�J WebLogic �D���x�C
  10. �s��ܥH�U��m�G
  11. yourdomain> Servers> myserver> Configure Keystores

  12. ���ۭq����M Java Standard Trust
  13. ��J����x�s�Ϧ�m�C�Ҧp�A/opt/bea81/keystore�C
  14. ��J����x�s�ϱK�X�M����x�s�ϳq��K�y�C�Ҧp�G
  15. ����x�s�ϱK�X�GJKS/Java Standard Trust (��� WL 8.1�A�o�ȬO JKS)

    ����x�s�ϳq��K�y�Gchangeit

  16. �o�ӨB�J�O����N��??????�Ьd�� SSL �p�K�K�_�]�w�p�K�K�_�O�W�Gmykey and passwd: secret12

  17. �Ƶ�

    �z�����ϥΧ���j�� SSL ���v�A�_�h SSL �ҰʱN�|����


  18. �b Access Manager ���AAmConfig.properties ���U�C�ѼƱN��w�˴v��۰ʰt�m�C�p�G���۰ʰt�m�A�z�i�H�A��a�s�襦�̡G
  19. com.sun.identity.jss.donotInstallAtHighestPriority=true [ this is not required for AM 6.3 and above]

    com.iplanet.security.SecureRandomFactoryImpl=com.iplanet.am.util.SecureRandomFactoryImpl

    com.iplanet.security.SSLSocketFactoryImpl=netscape.ldap.factory.JSSESocketFactory

    com.iplanet.security.encryptor=com.iplanet.services.util.JCEEncryption2

    �p�G�z�� JDK ��|�p�U�ҥܡG

    com.iplanet.am.jdk.path=/usr/jdk/entsys-j2se

    ����Шϥ���u�㤽�ε{���A�b���Ҹ�Ʈw���פJ Root CA�C�Ҧp�G

    /usr/jdk/entsys-j2se/jre/lib/security

    /usr/jdk/entsys-j2se/jre/bin/keytool -keystore cacerts -keyalg RSA -import -trustcacerts -alias "machinename" -storepass changeit -file

    /opt/bea81/cacert.txt

    ��u�㤽�ε{�����H�U�ؿ�G

    /usr/jdk/entsys-j2se/jre/bin/keytool

  20. �q Access Manager amadmin ��O�椽�ε{������ -D"java.protocol.handler.pkgs=com.iplanet.services.comm"�C
  21. �b SSL �Ҧ����t�m Access Manager�C�p�ݧ�h��T�A�аѾ\�b SSL �Ҧ����t�m Access Manager�C


�ϥΦw�� IBM WebSphere Application Server �t�m AMSDK

�b SSL ���ϥ� AMSDK �i��t�m���e�A������w�� IBM WebShpere Server �ðt�m�� Web �e���C�p�ݦw�˻���A�аѾ\ WebSphere ��A�������C�Y�n�� Access Manager �N WebLogic �t�m�� Web �e���A�аѾ\��  1 ���uAccess Manager 2005Q1 �t�m�{���� �v�C

�Y�n�t�m�w�� WebSphere ��ҡG

  1. �Ұ� ikeyman.sh (��� Websphere/bin �ؿ�)�C
  2. �q [ñ�W��] �\��?�פJ���ұ��v��� (CA) ���ҡC
  3. �q [�ӤH����] �\��?�� CSR�C
  4. �^��b�W�ӨB�J���إߪ����ҡC
  5. ��� [�ӤH����] �öפJ��A�����ҡC
  6. �q WebSphere �D���x�A�ܧ�w�] SSL �]�w�ÿ��K�X�C
  7. �]�w�w�] IBMJSSE SSL ���Ѫ̡C
  8. ��J�H�U��O�A�q�z��~�إߪ��ɮסA�N Root CA ���ҶפJ�� Application Server JVM ����x�s�ϡG
  9. $ appserver_root-dir/java/bin/ keytool -import -trustcacerts -alias cmscacert -keystore ../jre/lib/security/cacerts -file /full_path_cacert_filename.txt

    app-server-root-dir �O Application Server ���ڥؿ�A�B full_path_cacert_filename.txt �O�]�t���Ҥ��ɮת������|�C

  10. �b Access Manager ���A��s AmConfig.properties ���ѼƥH�ϥ� JSSE�G
  11. com.sun.identity.jss.donotInstallAtHighestPriority=true

    com.iplanet.security.SecureRandomFactoryImpl=com.iplanet.am.util.SecureRandomFactoryImpl

    com.iplanet.security.SSLSocketFactorImpl=netscape.ldap.factory.JSSESocketFactory

    com.iplanet.security.encyptor=com.iplanet.services.unil.JCEEncryption

  12. �b SSL �Ҧ����t�m Access Manager�p�ݧ�h��T�A�аѾ\�b SSL �Ҧ����t�m Access Manager�C


�b SSL �Ҧ����t�m Access Manager �� Directory Server

���F�b���W���Ѧw���q�T�AAccess Manager �]�t LDAPS �q�T��w�CLDAPS �O�зǪ� LDAP �q�T��w�A��� Secure Sockets Layer (SSL) ���h���C���ҥ� SSL �q�T�A�z������b SSL �Ҧ����t�m Directory Server�A�M��s�� Access Manager �� Directory Server�C�򥻨B�J�p�U�G

  1. ��o�P�w�� Directory Server �����ҡA�ðt�m Directory Server ��A���H�H�� [���ұ��v���] (CA) �����ҡC
  2. �}�ҥؿ� SSL�C
  3. �t�m�{�ҡB�����M���x�A�ȥH�s����ҥ� SSL �� Directory Server�C
  4. �t�m Access Manager �H�w���a�s���� Directory Server ��ݡC

�b SSL �Ҧ����t�m Directory Server

���F�b SSL �Ҧ����t�m Directory Server�A������o�ðt�m�@�Ӧ�A�����ҡA�t�m Directory Server �H�H�� CA ���Ҩñҥ� SSL�C����p�󧹦��o�Ǥu�@���Բӫ�ܡA�аѾ\�uDirectory Server �޲z��n�v���� 11 ���u�޲z�{�ҩM�[�K�v�C�������H�U��m�G

�z�]�i�H�q�U�C��m�U���U�� PDF �ɡG

http://docs.sun.com/coll/DirectoryServer_04q2 �P http://docs.sun.com/coll/DirectoryServer_04q2_zh_TW

�p�G�z�� Directory Server �w�g�ҥ� SSL�A�e���U�@�`�H�ѦҦ���s�� Access Manager �� Directory Server ���ԲӸ�ơC

�s�� Access Manager ��ҥ� SSL �� Directory Server

�N Directory Server �t�m�� SSL �Ҧ���A�z�����w���a�N Access Manager �s���� Directory Server ��ݡC�Y�n�p���A�СG

  1. �b Access Manager �D���x���A�e���A�Ȱt�m�Ҳժ� LDAP �{�ҪA�ȡC
    1. �ܧ� Directory Server �s���� SSL �s����C
    2. ��ܱҥι� LDAP ��A���ݩʪ� SSL �s��C
  2. �e���A�Ȱt�m�Ҳդ���������Y�{�ҪA�ȡC
    1. �ܧ� Directory Server �s���� SSL �s����C
    2. ��ܱҥι� LDAP ��A���ݩʪ� SSL �s��C
  3. �e�����A�Ȱt�m���������t�m�A�ȡC
    1. �ܧ� Directory Server �s���� SSL �s����C
    2. ��� LDAP SSL �ݩʡC
  4. �b��r�s�边���}�� serverconfig.xml�C���ɮצ��H�U��m�G
  5. etc/opt/SUNWam/config

    1. �b <Server> ���󤤡A�ܧ�U�C�ȡG
    2. port - ��J Access Manager ��ť���w���s����� (�w�]�� 636)�C

      type - �ܧ� SIMPLE �� SSL�C

    3. �x�s���� serverconfig.xml�C
  6. �q�H�U�w�]��m�}�� AMConfig.properties �ɮסG
  7. AcessManager-base/SUNWam/config

    �ܧ�U�C�S�ʡG

    1. Directory Port = 636 (�Y�ϥιw�]��)
    2. ssl.enabed = true
    3. �x�s AMConfig.properties�C
  8. ���s�Ұʦ�A���C




�W�@��      �ؿ�      �d�      �U�@��     


��󸹽X�G819-1941�C Copyright 2005 Sun Microsystems, Inc. ���v�Ҧ��C