
Preparing the Applications and the J2EE Servers
69
n
ov
do
cx (e
n)
16
Ap
ril 20
10
Two parameters are defined in this servlet: the
postLogoutURL
parameter and the
WebsphereLTPAMechanism
parameter.
The URL pattern of the LogoutServlet can be customized for the application's requirements. To
cause the LogoutServlet to notify the Identity Server about a user logging out, the user is
redirected to the URL in the Web module as specified by the postLogoutURL servlet
initialization parameter. If it is not specified, the LogoutServlet defaults the postLogoutURL to
/
.
The
<param-value>
for the
WebsphereLTPAMechanism
parameter is set to
false
by default.
When the WebSphere server is configured to use the LTPA authentication mechanism, the
<param-value>
must be set to
true
so that when the global logout is performed, the Novell
J2EE Agent clears the LTPA cookie.
If the
<param-value>
is not set to
true
and the LTPA cookie is not cleared during the logout,
the users have problems connecting from a browser that was not closed after a previous logout.
This
<param-value>
is also available in the
web.xml
file of the sample PayrollApps.
More than one
<url-pattern>
value can be specified for the LogoutServlet. The function of the
LogoutServlet is to notify the Identity Server about the application logout. The Identity Server is
responsible for notifying all other components about the logout.
4.2 Configuring Applications on the JBoss
Server
Section 4.2.1, “Configuring a Security Domain,” on page 69
Section 4.2.2, “Configuring Security Constraints,” on page 70
Section 4.2.3, “Configuring for Roles,” on page 70
4.2.1 Configuring a Security Domain
JBoss needs to know that your Web application is a part of the security domain that requires the
Identity Server JAAS login module. You do this by specifying your application's security domain in
the
<jboss-web>
element of the
jboss-web.xml
file located in your application’s
WEB-INF
directory. You might need to create this file, if your application hasn’t already required you to create
it.
The J2EE Agent installation program modifies the
login-config.xml
file in the
${JBOSS_HOME}/
server/default/conf
directory and sets the name attribute of the
<application-policy>
element to
novell-idp
.
You need to set the
<security-domain>
element in the
jboss-web.xml
file to this value. Add the
following lines to this file:
<jboss-web>
<security-domain>java:jaas/novell-idp</security-domain>
</jboss-web>
The
jboss-web.xml
file of the sample application (
PayrollApp.ear
) has these modifications.
(For the location of this application, see
Section 2.1, “Prerequisites,” on page 45
.)
Содержание Access Manager 3.1 SP 2
Страница 4: ...4 Novell Access Manager 3 1 SP2 J2EE Agent Guide novdocx en 16 April 2010...
Страница 8: ...8 Novell Access Manager 3 1 SP2 J2EE Agent Guide novdocx en 16 April 2010...
Страница 44: ...44 Novell Access Manager 3 1 SP2 J2EE Agent Guide novdocx en 16 April 2010...
Страница 83: ...Preparing the Applications and the J2EE Servers 83 novdocx en 16 April 2010...
Страница 108: ...108 Novell Access Manager 3 1 SP2 J2EE Agent Guide novdocx en 16 April 2010...