
Configuring the Agent for Authentication
2
45
n
ov
do
cx (e
n)
16
Ap
ril 20
10
2
Configuring the Agent for
Authentication
You can configure the Access Manager to interact with your application server.
You can configure it as an identity provider for the user authentication and user roles. In this
configuration, the application server is accessed directly by the user, and the agent is
configured to redirect the user to the Identity Server for authentication and user roles. If you
need the security of SSL, you need to configure the application server for SSL.
You can configure it as a protected resource of the Access Gateway. When the agent is
configured to be an Access Gateway protected resource, the IP address of the application server
is hidden from the user and the user must access it through the Access Gateway. You can
configure the Access Gateway to require SSL connections without configuring the application
server for SSL.
This section has the following information.
Section 2.1, “Prerequisites,” on page 45
Section 2.2, “Possible Configurations,” on page 45
Section 2.3, “Configuring the Agent for Direct Access,” on page 47
Section 2.4, “Configuring Authentication Contracts,” on page 49
Section 2.5, “Protecting the Application Server with the Access Gateway,” on page 53
2.1 Prerequisites
You have set up a basic configuration. See “
Setting Up a Basic Access Manager Configuration
”
in the
Novell Access Manager 3.1 SP2 Setup Guide
.
You have a J2EE application server that has an application with security constraints.
You have configured the Identity Server with policies for the roles required by your
application. For the sample payroll application, this is an Employee role and a Manager role.
You have the agent installed on your J2EE server. See
Chapter 1, “Installing the J2EE Agents,”
on page 11
.
2.2 Possible Configurations
The J2EE server uses the Identity Server for authentication.You can configure your J2EE server in
such a way that either the users have direct access to it or the J2EE server is a protected resource of
the Access Gateway.
Section 2.2.1, “Allowing Direct Access to the J2EE Server,” on page 46
Section 2.2.2, “Protecting the Application Server with the Access Gateway,” on page 46
Содержание Access Manager 3.1 SP 2
Страница 4: ...4 Novell Access Manager 3 1 SP2 J2EE Agent Guide novdocx en 16 April 2010...
Страница 8: ...8 Novell Access Manager 3 1 SP2 J2EE Agent Guide novdocx en 16 April 2010...
Страница 44: ...44 Novell Access Manager 3 1 SP2 J2EE Agent Guide novdocx en 16 April 2010...
Страница 83: ...Preparing the Applications and the J2EE Servers 83 novdocx en 16 April 2010...
Страница 108: ...108 Novell Access Manager 3 1 SP2 J2EE Agent Guide novdocx en 16 April 2010...