Escolar Documentos
Profissional Documentos
Cultura Documentos
0
Deployment and Administration Workshop
Student’s Training Guide
S150-3032-00
September 2008
Copyright Notice
Copyright © 2008 IBM Corporation, including this documentation and all software. All rights
reserved. May only be used pursuant to a Tivoli Systems Software License Agreement, an IBM Soft-
ware License Agreement, or Addendum for Tivoli Products to IBM Customer or License Agreement.
No part of this publication may be reproduced, transmitted, transcribed, stored in a retrieval system,
or translated into any computer language, in any form or by any means, electronic, mechanical,
magnetic, optical, chemical, manual, or otherwise, without prior written permission of IBM Corpora-
tion. IBM Corporation grants you limited permission to make hardcopy or other reproductions of any
machine-readable documentation for your own use, provided that each such reproduction shall carry
the IBM Corporation copyright notice. No other rights under copyright are granted without prior writ-
ten permission of IBM Corporation. The document is not intended for production and is furnished “as
is” without warranty of any kind. All warranties on this document are hereby disclaimed, including the
warranties of merchantability and fitness for a particular purpose.
Note to U.S. Government Users—Documentation related to restricted rights—Use, duplication or
disclosure is subject to restrictions set forth in GSA ADP Schedule Contract with IBM Corporation.
Trademarks
The following are trademarks of IBM Corporation or Tivoli Systems Inc.: IBM, Tivoli, AIX, Cross-Site,
NetView, OS/2, Planet Tivoli, RS/6000, Tivoli Certified, Tivoli Enterprise, Tivoli Ready, TME. In Den-
mark, Tivoli is a trademark licensed from Kjøbenhavns Sommer - Tivoli A/S.
Microsoft, Windows, Windows NT, and the Windows logo are trademarks of Microsoft Corporation in
the United States, other countries, or both.
UNIX is a registered trademark of The Open Group in the United States and other countries.
C-bus is a trademark of Corollary, Inc. in the United States, other countries, or both.
Java and all Java-based trademarks are trademarks of Sun Microsystems, Inc. in the United States,
other countries, or both.
Lotus is a registered trademark of Lotus Development Corporation.
PC Direct is a trademark of Ziff Communications Company in the United States, other countries, or
both and is used by IBM Corporation under license.
ActionMedia, LANDesk, MMX, Pentium, and ProShare are trademarks of Intel Corporation in the
United States, other countries, or both.
SET and the SET Logo are trademarks owned by SET Secure Electronic Transaction LLC. For fur-
ther information, see http://www.setco.org/aboutmark.html.
Other company, product, and service names may be trademarks or service marks of others.
Notices
References in this publication to Tivoli Systems or IBM products, programs, or services do not imply
that they will be available in all countries in which Tivoli Systems or IBM operates. Any reference to
these products, programs, or services is not intended to imply that only Tivoli Systems or IBM prod-
ucts, programs, or services can be used. Subject to valid intellectual property or other legally pro-
tectable right of Tivoli Systems or IBM, any functionally equivalent product, program, or service can
be used instead of the referenced product, program, or service. The evaluation and verification of
operation in conjunction with other products, except those expressly designated by Tivoli Systems or
IBM, are the responsibility of the user. Tivoli Systems or IBM may have patents or pending patent
applications covering subject matter in this document. The furnishing of this document does not give
you any license to these patents. You can send license inquiries, in writing, to the IBM Director of
Licensing, IBM Corporation, North Castle Drive, Armonk, New York 10504-1785, U.S.A.
Printed in Ireland.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
1
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Course Objectives
Upon completion of this course, you will be able to:
• Describe the components of IBM Tivoli Access Manager for
Enterprise Single Sign-On 8.0.
• Install and configure the IBM Tivoli Access Manager for Enterprise
Single Sign-On 8.0 server.
• Configure machine profiles for groups of personal or shared
workstations.
• Deploy the access agent component for desktop single sign-on.
• Use Access Studio to create template-based single sign-on profiles.
• Use Access Studio to create advanced single sign-on profiles.
• View reports and audit information.
• Perform a simple integration with IBM Tivoli Identity Manager 5.0.
2
2
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Unit 1: Overview
1-1
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Objectives
1-2
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Strong Authentication
1-3
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Web
Desktop Citrix or Terminal
Services Desktop
1-4
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
1-5
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
AccessAgent Overview
Authentication
Factors
Central
Administration
AccessAgent
Automated Actions
Plug-ins
Automation Triggers
Wallet
Observer Framework
1-6
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Product Components
• TAM E-SSO AccessAgent
Client software that manages user identity
Enables sign-on and sign-off automation
• TAM E-SSO IMS Server
Identity management system that enables centralized management of
user identities, AccessProfiles, and policies
• TAM E-SSO AccessAdmin
Management console for IMS Server
Accessed by administrator and helpdesk users
• TAM E-SSO AccessAssistant
Web-based password self-help
1-7
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
1-8
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Platform Support
• TAM E-SSO AccessAgent runs on the following client platforms:
Windows 2000
Windows XP
Windows XP Tablet edition
Windows Terminal Services running on Windows Server 2000
Windows Terminal Services running on Windows Server 2003
Citrix Metaframe (XP) FR2 and above
Citrix Metaframe Presentation Server 3.0 and above
• TAM E-SSO also supports thin client platforms. On these platforms,
the TAM E-SSO AccessAgent runs on Citrix or Terminal Services:
Windows CE
Windows XPE
• The TAM E-SSO IMS server runs on any Windows 2000 server and
later.
1-9
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Summary
10
1-10
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Unit 2: Server
2-1
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Objectives
2-2
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
2-3
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Database Options
• Support databases:
IBM DB2 9.5
Microsoft SQL Server 2000 Desktop Engine (MSDE)
Microsoft SQL Server 2000 or SQL Server 2005
Microsoft SQL Express
Oracle 9i, 10g
• IMS Express Install
Installs Microsoft SQL Express
Prerequisites:
– Microsoft Data Access Components (MDAC) 2.8 SP1 or later
– Microsoft Windows Installer 3.1
– Microsoft .NET Framework 2.0
2-4
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
2-5
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
2-6
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Express Installation
2-7
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
2-8
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
2-9
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Custom Installation
10
2-10
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
11
2-11
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
12
2-12
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
13
2-13
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
14
2-14
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
15
2-15
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
16
2-16
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
17
2-17
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Installation Completion
18
2-18
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
19
2-19
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Password Synchronization
20
2-20
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Administrator Credentials
21
2-21
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
22
2-22
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
23
2-23
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
24
2-24
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
25
2-25
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
26
2-26
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
OutOfMemory Exceptions
27
2-27
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Student Exercise
28
2-28
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Summary
29
2-29
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Unit 3: Policies
3-1
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Objectives
3-2
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Policies
3-3
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
3-4
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
3-5
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Policy Priority
3-6
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Policy Dependencies
3-7
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
AccessAdmin
3-8
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
3-9
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
10
3-10
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
11
3-11
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
12
3-12
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
• A unified AccessAgent user interface supports sign up, log on, lock,
and unlock for:
USB Key
RFID
Active RFID (ARFID)
Fingerprint
• A two phase registration is possible.
Users can sign up with a password and an optional second factor.
Users can also register a second factor during a grace period.
After the grace period, all users must log on with a second factor.
• You can revoke second factors using AccessAdmin.
13
3-13
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
RFID
• Suggested second factor for shared workstations
• Password required, except for RFID-only unlock
• Supported cards:
HID 125kHz Proximity Card
HID iClass
Mifare (Ultralight, 1k, 4k)
• Supported readers:
RF IDeas pcProx Readers (for 125kHz cards)
RF IDeas AIR Contactless Smart Card Readers (iClass and Mifare)
GIGA-TMS Proximity Reader MFR135 (PCMCIA)
Altrus Mifare Desktop Reader Writer A1
14
3-14
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
ARFID
15
3-15
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
ARFID (continued)
• Hardware from different countries is not interoperable.
• Must be cautious of interference.
Line of sight between key and lock is preferred.
Water can significantly reduce signal strength.
Metallic objects can block radio signal.
900MHz cordless phones can interfere with North American hardware.
• Key turns off automatically after 9 hours.
• Battery:
Can be replaced.
Has an average life of one year.
Maintains constant power until a couple of weeks before it needs to be
replaced.
16
3-16
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Fingerprint
17
3-17
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
USB Key
18
3-18
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
19
3-19
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
20
3-20
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
21
3-21
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
22
3-22
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
23
3-23
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
24
3-24
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
25
3-25
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
26
3-26
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
27
3-27
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
28
3-28
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
29
3-29
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
30
3-30
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
31
3-31
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
32
3-32
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
33
3-33
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
34
3-34
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
35
3-35
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Modifying Policies
36
3-36
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Student Exercise
37
3-37
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Summary
38
3-38
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Unit 4: Agent
4-1
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Objectives
4-2
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
• AccessAgent.msi
• Config folder
• Reg folder
4-3
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
4-4
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
SetupHlp.ini Options
4-5
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
4-6
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
• Steps:
1. Prepare a bitmap file with a size of 432x64 pixels.
2. Name the file logon_banner.bmp.
3. Place the file in the installer Config folder.
– The installer will automatically copy the file to the program files
folder.
– The file can also be manually copied if AccessAgent is already
installed.
• Appears on:
TAM E-SSO GINA welcome, logon, lock, and unlock windows.
Desktop AccessAgent window.
4-7
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Client Prerequisites
4-8
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
4-9
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
10
4-10
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Successful Installation
11
4-11
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Workstation Restart
12
4-12
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
13
4-13
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
14
4-14
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
User Sign-Up
15
4-15
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Secrets
• Set by user during sign-up by
selecting questions from the
pid_bind_secret_question_list
policy.
• Should be:
Easy to remember.
Permanent in nature.
Not easily made known to others.
• Used when password is not
available such as during a
password reset.
16
4-16
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
17
4-17
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Automatic Logon
18
4-18
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Wallet
19
4-19
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Wallet Concepts
• Authentication policy is pid_wallet_authentication_option.
• Stored on the IMS Server. However, some parts can also be stored
in an authentication factor such as a private key on smart card.
• Roams to any point of access.
Accessible with appropriate combination of authentication factors.
• Wallets can be:
In memory (does not contain certificate or one-time password (OTP)
seed).
Cached on hard disk or USB key (for offline access including offline
bypass and password reset).
• Wallets can be revoked by a user with the administrator or helpdesk
role using AccessAdmin.
20
4-20
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Wallet Locks
21
4-21
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
22
4-22
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Managing Credentials
23
4-23
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
• Program files:
C:\Program Files\Encentuate
• Logs”
C:\Program Files\Encentuate\logs
To send to support:
– Right-click folder and select Send To > Compressed (zipped)
Folder.
– Save as AAlogs.zip.
• User and machine wallets (hidden files):
C:\Program Files\Encentuate\Cryptoboxes
The machine wallet (machine.wlt) contains system policies and
AccessProfiles downloaded from IMS Server
24
4-24
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
• Debugging:
Useful to increase log level for more debugging information.
Set machine policy pid_log_level.
Log level 3 is suggested.
Can be set to 4 if more detailed logs are needed.
• XML files in the logs folder indicate communications with
IMS Server.
• AccessAgent.log logs internal AccessAgent processes.
• When reporting a problem to support:
Include a compressed file containing the C:\Program
Files\Encentuate\logs folder.
Provide approximate local times at which events occurred.
25
4-25
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Certificate Download
26
4-26
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
AccessAgent Cryptoboxes
27
4-27
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
28
4-28
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
29
4-29
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
30
4-30
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Student Exercise
31
4-31
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Summary
32
4-32
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Unit 5: Roles
5-1
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Objectives
5-2
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Roles
5-3
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
5-4
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
5-5
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
5-6
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
5-7
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Administrator Users
5-8
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Helpdesk Users
• Are part of a defined identity confirmation process.
• Manage users and authentication factors.
• Provide second authentication factors to new employees.
• Replace lost second authentication factors.
• Maintain second authentication factors.
• Help with forgotten passwords.
• De-provision departing employees.
• Promote good security practices.
Choose strong password
Do not forget the secret
Safeguard the desktop
Report loss of a second authentication factor
• Troubleshoot.
5-9
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
10
5-10
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
11
5-11
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
12
5-12
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
13
5-13
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Authorization Code
5-14
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
15
5-15
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
16
5-16
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
17
5-17
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
18
5-18
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
19
5-19
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
20
5-20
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
21
5-21
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
22
5-22
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
23
5-23
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Instructor Demonstration
24
5-24
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Recovery Workflows
• User
Forgets password
Forgets or loses second factor
Cannot unlock computer
25
5-25
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
• Online • Offline
1. Click Reset password. 1. Click Reset password.
2. Supply authorization code and 2. Supply authorization code
secret. (based on request code).
3. Specify new TAM E-SSO 3. Supply secret.
password. 4. Specify temporary password.
Note: Cached wallets might still Note: User can log on multiple times
contain old password. using temporary password until
authorization code expires.
26
5-26
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
1. Reset the Active Directory password using Active Directory Users and
Computers.
2. Have the user login to TAM E-SSO with the new Active Directory
password.
3. AccessAgent prompts for the answer to the user’s secret question and
then synchronizes the Active Directory password with TAM E-SSO.
27
5-27
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Note: User can log on multiple times Note: User can log on multiple times
without RFID card until authorization using temporary password until
code expires. authorization code expires.
28
5-28
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
• Conditions:
Computer must be a shared workstation with Emergency Bypass
enabled.
– Emergency Bypass is disabled by default.
User might not have cached wallet on computer.
IMS Server is not available.
• Steps:
Press Emergency Bypass key sequence.
Computer unlocks immediately.
Users who are currently logged on will be logged off.
29
5-29
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
• Launch AccessAssistant.
• Supply user name and password.
• Depending on the policy, the user might need to supply
authorization code or Mobile ActiveCode.
• User can now obtain enterprise application passwords.
30
5-30
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
31
5-31
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
32
5-32
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
33
5-33
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Student Exercise
34
5-34
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Summary
35
5-35
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
6-1
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Objectives
6-2
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
6-3
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
6-4
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
6-5
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
6-6
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
• Lock
User can tap RFID card to lock computer.
Computer is also locked after a period of inactivity.
• Unlock
Tap RFID card or press Ctrl-Alt-Del to unlock.
Computer unlocks without password if user is back within
configurable period.
6-7
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
• Shared desktop
Different user can tap RFID card to invoke switching of user, from
desktop or lock computer screen.
AccessAgent will unlock computer (if locked), log off previous user,
and log on to the wallet of the new user.
• Private desktop
Different user can tap RFID card to invoke switching of user, from
desktop or lock computer screen.
AccessAgent will lock the previous user session (if unlocked), and
log on to the wallet and Windows session of the new user.
Forced log off will occur during user switching if the maximum
number of sessions is exceeded.
6-8
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
• Shared desktop
Right-click and select Log off AccessAgent or press Ctrl-Alt-Del.
Log off also occurs during switch user.
Automatic log off or closing of applications can be performed.
Logoff script, if any, is run.
• Private desktop
Right-click and select Log off AccessAgent or press Ctrl-Alt-Del.
For a forced log off, one of the previous sessions will be closed
depending on the algorithm selected.
The number of maximum sessions and log off algorithm are
configured in shared workstation policy.
6-9
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
10
6-10
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Student Exercise
11
6-11
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Summary
12
6-12
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
7-1
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Objectives
7-2
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
7-3
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
User Credentials
7-4
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Application
7-5
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Authentication Service
7-6
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Yahoo! Messenger
7-7
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
AccessStudio Overview
7-8
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
7-9
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
10
7-10
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
7-11
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Generating an AccessProfile
12
7-12
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
13
7-13
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
14
7-14
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
15
7-15
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
16
7-16
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
17
7-17
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
18
7-18
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
19
7-19
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
20
7-20
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
21
7-21
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Start Testing
22
7-22
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
23
7-23
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Save Credentials
24
7-24
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
25
7-25
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
26
7-26
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
27
7-27
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
28
7-28
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
29
7-29
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
30
7-30
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
31
7-31
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
32
7-32
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
33
7-33
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
34
7-34
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
35
7-35
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
36
7-36
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Uploading AccessProfiles
37
7-37
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
38
7-38
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Deleting AccessProfiles
• The profile must have been loaded from the IMS Server.
• Right-click the Profile, select Delete, and answer Yes to
also delete from IMS.
39
7-39
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Student Exercise
40
7-40
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Summary
41
7-41
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
8-1
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Objectives
8-2
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
State Machine
• Functions (logging in to an application, changing passwords, and so
on) modeled as a sequence of steps represented by states and
transitions.
• Consists of states, triggers, and actions.
• The AccessProfile is designed to model these sequences leveraging
its ability to monitor and interpret events on a user’s desktop.
8-3
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Start State
State After
Injection
8-4
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
States
8-5
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Triggers
• Triggers are events that cause transitions between states in the
state engine.
• Examples of a trigger:
– wnd_create_trigger: Windows executable window is created.
– web_document_complete_trigger: Web document completes loading.
– web_click_item_trigger: HTML element clicked.
– wnd_command_bn_click_trigger: Windows executable button clicked.
• Each trigger has a next state defined.
For example, when a login window is presented, the state machine
could move to the after_login_window_popped_up state.
• There are approximately 40 predefined triggers.
8-6
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Actions
8-7
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Signatures
8-8
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
XPaths
8-9
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
10
8-10
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
11
8-11
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
XPath Operators
• = (right hand side (RHS) can be numeric or string, equals)
• != (RHS must be numeric, not equals)
• ~ (RHS must be a string, regex case-sensitive equals)
• !~ (RHS must be a string, regex case-sensitive not equals)
• # (RHS must be a string, regex case-insensitive equals)
• !# (RHS must be a string, regex case-insensitive not equals)
• & (RHS must be a numeric, binary AND)
• !& (RHS must be numeric, not equals of binary AND)
• and (Logical AND of two booleans)
• or (Logical OR of two booleans)
12
8-12
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
13
8-13
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
14
8-14
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
15
8-15
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
16
8-16
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
17
8-17
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
18
8-18
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
19
8-19
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
20
8-20
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
21
8-21
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
22
8-22
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
23
8-23
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
24
8-24
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
25
8-25
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
26
8-26
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
27
8-27
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
28
8-28
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
29
8-29
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
30
8-30
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
31
8-31
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
32
8-32
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
33
8-33
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
34
8-34
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
35
8-35
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
36
8-36
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
37
8-37
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
38
8-38
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
39
8-39
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
40
8-40
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
41
8-41
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
42
8-42
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
43
8-43
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
44
8-44
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
45
8-45
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
46
8-46
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
47
8-47
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
This step tells the state engine where to go after the trigger actions
in the Start State are complete.
1. Click the When a window is activated (Win32) trigger.
2. Select state_after_injection for the next state.
48
8-48
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
1. Right-click state_after_injection.
2. Select When a button is clicked trigger.
49
8-49
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
50
8-50
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
• This action will capture the credentials so they can be saved to the
wallet.
• Right-click the trigger and select Add Action > Captures user
credentials.
51
8-51
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
52
8-52
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
53
8-53
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
54
8-54
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
55
8-55
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
56
8-56
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
57
8-57
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
58
8-58
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
59
8-59
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
60
8-60
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
61
8-61
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
62
8-62
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
• Spy++
• Winspector
• Process Explorer
• DOM Inspector
63
8-63
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
64
8-64
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Suggested Practices
65
8-65
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Student Exercise
66
8-66
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Summary
67
8-67
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
9-1
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Objectives
9-2
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Auditing
9-3
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
9-4
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
9-5
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Reporting
• User
• Token
• Application
• Helpdesk
9-6
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
9-7
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
9-8
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
9-9
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
10
9-10
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
11
9-11
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
12
9-12
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
13
9-13
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Housekeeping
14
9-14
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
General Housekeeping
15
9-15
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
16
9-16
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Student Exercise
17
9-17
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Summary
18
9-18
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
10-1
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Objectives
10-2
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
10-3
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
10-4
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
10-5
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
High Availability
10-6
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
10-7
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
10.0.0.11 10.0.0.12
tamesso1 tamesso2
10.0.0.21 10.0.0.22
10-8
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
10-9
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
10
10-10
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
11
10-11
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Network
SQL Server Virtual Server
MSCS MSCS
Heartbeat
Node 1 Node 2
Shared Disk
12
10-12
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
DB2 Server
Primary Node
DB2 Client
13
10-13
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
14
10-14
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
15
10-15
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
16
10-16
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
17
10-17
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
10-18
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Summary
19
10-19
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
11-1
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Objectives
11-2
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
11-3
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
11-4
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
11-5
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
11-6
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
11-7
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
11-8
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
11-9
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Student Exercise
10
11-10
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
IBM Tivoli Access Manager for Enterprise Single Sign-On 8.0 Deployment and Administration Workshop
Summary
11
11-11
©Copyright IBM Corp. 2008 Course materials may not be reproduced in whole or in part without the prior written permission of IBM.