Home > AS/400 Tips > WebSphere Strategies for iSeries professionals > Basic security considerations for a Domino/WebSphere system
iSeries 400 Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WEBSPHERE STRATEGIES FOR ISERIES PROFESSIONALS

Basic security considerations for a Domino/WebSphere system


Sue Hildreth
01.10.2006
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Lotus Domino and WebSphere Portal are a perfect combination for creating collaborative e-business environments. But, as with any collaborative application or portal that enables access to corporate data over the Internet, security considerations becomes a serious concern.
Don't have time to read this tip?
Download the audiocast

There are many guidelines for creating a more secure WebSphere Domino system, available in documentation on the IBM Web site. The most recent IBM Redbook on the topic, WebSphere Portal Collaboration Security Handbook, offers advice on implementing three major security requirements specifically for a WebSphere Portal server connecting to Lotus Team Workplace and Lotus Instant Messaging and Web Conferencing.

Traffic encryption

To prevent sensitive data from being intercepted as it travels over the wire, traffic must be encrypted. Secure Sockets Layer (SSL) has become the most common method for creating an encrypted connection between client and server, and for authenticating both the server and client machines.

There are three communication protocols between the WebSphere Portal Collaborative Services and back-end Lotus Domino servers that need to be configured for SSL: HTTP, DIIOP and LDAP. Both Domino and WebSphere Portal must be configured for SSL.

User authentication

Obviously, you want to know that only authorized people are accessing your systems. Standard authentication methods include user ID and password, SSL certificates exchanged between client and server, and a user's listing in a corporate directory using LDAP, the industry standard for Internet and intranet-based directories.

SSL in Domino products can be implemented via signed certificates from a certificate authority such as VeriSign. To enable SSL in WebSphere Portal, you have to configure SSL for the IBM HTTP server, as well as the WebSphere Application Server plug-in for the Web server, and, finally the WebSphere Portal (as described in the IBM Redbook Chapter 5.4.1 to 5.4.3). SSL also must be enabled for the LDAP connections in WebSphere.

There are additional authentication mechanisms that WebSphere uses. The Lightweight Third Party Authentication (LTPA) token, for example, enables secure communication between Portal and Lotus collaborative applications.

When a user logs on to the Portal to access a Lotus application, the LDAP directory server creates an LTPA token that resides on the user's Web browser as a session cookie that can be passed to, and read by, multiple back-end Domino servers.

WebSphere has additional authentication tools, including the Credential Vault for use by portlets that need to access back-end system. The Credential Vault provides a place for portlets to access user credentials such as password and SSL certificate after the user has logged on, providing single sign-on for the user.

Function authorization

Not every user should have access to every resource or function. Good security requires that different user groups be granted different levels of access to corporate systems. WebSphere Application Server accomplishes this via the J2EE security mechanisms, which include security roles.

Developers can create generic security roles for various departments or types of employees, and provide those roles with access to the specific resources and functions they require. For instance, accounting and human resources employees may be given the ability to run a payroll query, whereas the marketing group cannot. Generic roles can then be mapped to actual users later.

Another option is to use IBM's Tivoli Access Manager, which can provide front-end authentication and authorization for the Web server. The Access Manager provides additional security for the Web and application servers by using a reverse proxy in the DMZ, outside the firewall, to receive traffic from the Internet and forward them to the Access Manager for authentication and authorization.

About the author: Sue Hildreth is a freelance technology writer based in Waltham, MA. She can be reached at Sue.Hildreth@comcast.net.

Do you have comments on this tip? Let us know.

Related information from SearchDomino.com:

  • Ask the Expert: What is WebSphere?
  • Tip: Understanding WebSphere v5 architecture
  • Learning Guide: WebSphere Portal


    Rate this Tip
    To rate tips, you must be a member of Search400.com.
    Register now to start rating these tips. Log in if you are already a member.




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    WebSphere Strategies for iSeries professionals
    Application modernization strategies for System i
    Application modernization in the i world
    Natively supported Web applications for Power running i
    Enterprise open source basics
    Simplifying data access using Java Standard Tag Library
    Integrating Microsoft ActiveX components with WebSphere
    Choices for running Web workloads on iSeries
    Virtual hosting for iSeries Web applications
    Automate WebSphere configuration backups on the iSeries (i5)
    Squirrel: The universal SQL client

    iSeries managed email and groupware
    System i document management tips
    IBM releases DB2 email archiving hardware and software
    Email to pager over iSeries
    Using the SNDDST command to e-mail extraction data
    Options for accepting or declining rescheduled meetings
    Lotus updates Workplace apps and Notes roadmap
    Partners shoulder hopes for Domino's future
    IBM unveils new software model with Workplace 2.0
    IBM delivers middleware for utilities, government markets
    What's Domino's destiny?
    iSeries managed email and groupware Research

    Web Development
    Application modernization strategies for System i
    RPG application modernization for i5
    Web skills crucial to iSeries programmer professional development
    System i Web interface could boost the platform
    Free System i development tools rebuttal
    COMMON product round-up: Modernizing the IBM System i
    Top 10 System i white papers
    Enterprise open source basics
    Make WebSphere work for you
    WebSphere for System i tutorial

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    WebSphere Development Studio Client (WDSC)  (Search400.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



  • iSeries Security - Security Tools, Physical Security and System Security
    HomeNewsTopicsITKnowledge ExchangeTipsBlogsAsk the ExpertsMultimediaWhite PapersProducts
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 1999 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts