IBM Security Directory Integrator: Installation and Administrator Guide Chapter 8
Total Page:16
File Type:pdf, Size:1020Kb
IBM Security Directory Integrator Version 7.2 Installation and Administrator Guide SC27-2705-02 IBM Security Directory Integrator Version 7.2 Installation and Administrator Guide SC27-2705-02 Note Before using this information and the product it supports, read the general information under Appendix D, “Notices,” on page 351. Edition notice Note: This edition applies to version 7.2 of IBM Security Directory Integrator licensed program (5724-K74) and to all subsequent releases and modifications until otherwise indicated in new editions. © Copyright IBM Corporation 2003, 2013. US Government Users Restricted Rights – Use, duplication or disclosure restricted by GSA ADP Schedule Contract with IBM Corp. Contents Figures ...............ix Installing or Updating using the Eclipse Update Manager ...............47 About this publication ........xi Post-installation steps ..........49 Uninstalling ..............50 Access to publications and terminology .....xi Launching the uninstaller.........50 IBM Security Directory Integrator library ....xi Performing a silent uninstallation ......51 Online publications............xii Default installation locations.........51 Related information ...........xii IBM Terminology website .........xiii Accessibility ..............xiii Chapter 3. Update Installer ......53 Technical training ............xiii The .registry file .............55 Support information ...........xiii Installing fixes .............56 Statement of Good Security Practices .....xiii Rollback ...............57 Troubleshooting .............57 Chapter 1. Introduction ........1 IBM Security Directory Integrator Version 7.2 Chapter 4. Supported platforms ....59 Editions ................1 Chapter 5. Migrating .........61 Chapter 2. Installation instructions for Migrate files to a different location ......61 IBM Security Directory Integrator ....3 Which files do not need to be modified to be Before you install .............3 used in another location? .........61 Disk space requirements .........3 Which files need to be modified before they can Memory requirements ..........3 be used in another location? ........62 Platform requirements ..........3 Which files should not be used in another Components in IBM Security Directory Integrator 3 location under normal circumstances? ....63 Other requirements ...........5 Migrating files that contain encrypted data . 63 Root or Administrator Privileges......5 Migrate files to a newer version .......63 Security Enhanced (SELinux) .......5 Installer-assisted migration ........63 Authentication of AMC on Unix/Linux . 6 Tool-assisted migration .........64 Graphics packages for UNIX systems ....6 Manual migration ...........65 Prerequisites for CE on AIX operating system . 7 Backing up important data ........77 Prerequisite for upgrading from V7.1.1 to V7.2 Files backed up by the Installer......77 on Windows 2012 operating system.....7 Upgrade from version 6.0 to 7.1 ....77 Installing IBM Security Directory Integrator ....7 Upgrade from version 6.1.x to 7.1 ....77 Launching the appropriate installer ......8 Upgrade from version 7.0 to 7.1 ....77 Using the platform-specific IBM Security Upgrade from version 7.1 to 7.1.1 ....78 Directory Integrator installer........10 Upgrade from version 7.1 to 7.1.1 ....78 Installing using the graphical installer ....11 Backup tools ............78 Install Panel flow ..........11 Manual backup ...........79 Uninstall Panel flow .........32 Migrating AMC 7.x configuration settings to another Add Feature Panel flow ........36 AMC deployment ............79 Migration Panel flow .........39 Converting from EventHandlers to corresponding Installing using the command line ......41 AssemblyLines .............80 Temporary file space usage during installation . 42 TCP Server Connector ..........81 Performing a silent install ........43 Mailbox Connector ...........81 Service name limitation on UNIX systems . 43 JMX Connector ............82 Post-installation steps ..........43 SNMP Server Connector .........82 CE Update Site ...........43 IBM Security Directory Server Changelog Plug-ins .............43 Connector ..............82 Administration and Monitoring Console HTTP Server Connector .........83 (AMC) ..............43 LDAP Server Connector .........83 Documentation ...........44 Sun Directory Change Detection Connector. 83 Migration .............44 Active Directory Change Detection Connector . 84 Installing local Help files ..........44 z/OS LDAP Changelog Connector......85 Deploying AMC to a custom ISC SE or IBM DSMLv2SOAPServerConnector .......85 Dashboard Application Services Hub ......46 © Copyright IBM Corp. 2003, 2013 iii Migrating BTree tables and BTree Connector to Server API authentication setup examples 116 System Store ..............86 Server API Authorization ........117 Migrating Cloudscape database to Derby ....87 Authorization roles .........117 Migrating global and solution properties files using Server API User Registry .......119 migration tool .............88 Server Audit Capabilities ........122 Migrating Password plug-ins properties files using Auditing scope ...........123 migration tool .............89 Suppression of notifications ......123 Sending notifications .........124 Chapter 6. Security .........91 IBM Security Directory Integrator Server Instance Introduction ..............91 Security ...............124 Manage keys, certificates and keystores .....91 Stash File..............125 Background .............91 Server Security Modes .........125 Public/private keys and certificates ....91 Working with encrypted IBM Security Directory Secret keys ............92 Integrator configuration files .......126 Keystores .............92 Introduction ............126 Keys for SSL ............92 Separation of certificates for PKI Encryption Keys for encryption .........93 andSSL.............128 Tools ..............93 Creating an encrypted IBM Security List the contents of a keystore .......93 Directory Integrator configuration file from Create keys .............93 scratch .............128 Secure Sockets Layer (SSL) Support ......96 Using the cryptoutils command line tool 128 Server SSL configuration of IBM Security Editing an encrypted IBM Security Directory Directory Integrator components ......97 Integrator configuration file ......128 Client SSL configuration of IBM Security Standard IBM Security Directory Integrator Directory Integrator components ......98 encryption of global.properties or SSL client authentication .........98 solution.properties...........128 IBM Security Directory Integrator and Microsoft Encryption of properties in external property Active Directory SSL configuration .....99 files ...............128 Summary of properties for enabling SSL and The IBM Security Directory Integrator PKCS#11 support ...........100 Encryption utility ...........129 SSL example.............101 IBM Security Directory Integrator System Store IBM Security Directory Integrator component Security ...............131 as a server ............101 Miscellaneous Config File features ......132 IBM Security Directory Integrator component The "password" configuration parameter type 132 as a client ............102 Component Password Protection ......132 Remote Server API ...........102 Saving passwords to configured Properties 132 Introduction .............102 Protecting attributes from being printed in clear Configuring the Server API........104 text during tracing ..........133 Remote Server API access on a Virtual Encryption of IBM Security Directory Integrator Private Network ..........106 Server Hooks ............133 Server API access options ........107 Remote Configuration Editor and SSL ....134 Server API SSL remote access .......107 Using the Remote Configuration Editor . 134 Using Server API specific SSL properties . 107 Summary of configuration files and properties Using the standard SSL Java System dealing with security ...........135 properties ............108 Web Admin Console Security ........138 Server API authentication ........108 Miscellaneous security aspects........138 Local client session .........109 HTTP Basic Authentication ........138 Remote client session.........109 Lotus Domino SSL specifics .......138 JAAS authentication .........109 Certificates for the IBM Security Directory SSL-based authentication .......109 Integrator Web service Suite .......139 Username/password based authentication 110 Example Server certificate creation ....139 Authentication hook ........110 IBM WebSphere MQ Everyplace authentication LDAP Authentication support ......111 with mini-certificates ..........139 LDAP Authentication Configuration . 111 LDAP Authentication Logic .....112 Chapter 7. Reconnect Rule Engine 141 LDAP Group Support .......113 Introduction ..............141 Host based authentication .......115 Reconnect Rules ............141 Summary of Server API Authentication User-defined rules configuration .......143 options .............115 Examples..............143 Server API JMX layer does not support Exception considerations ........144 username and password authentication. 115 General reconnect configuration .......144 iv IBM Security Directory Integrator: Installation and Administrator Guide Chapter 8. System Queue ......147 Chapter 10. Configuring the IBM System Queue Configuration ........147 Security Directory Integrator Server Apache ActiveMQ parameters .......147 API................171 Configuration ...........148 Server ID ...............171 Logging .............148 Exception for password protected Configs ....171 Using SSL with ActiveMQ .......149