Forcing traffic to be sent over SSLAdded by IBM on February 11, 2013 | Version 1 (Original)
|You can configure IBM® Connections to force all traffic that passes between an IBM Connections server and a user's web browser to be sent over the Secure Socket Layer (SSL).
Before you begin
Be sure that SSL is enabled in your environment before you perform this procedure. See Configuring the IBM HTTP Server for SSL
in the Installing
section of the IBM
Connections product documentation for more information.
To edit configuration files, you must use the wsadmin client. See Starting the wsadmin client
Parent topic: Security
Changing common configuration property values
Starting the wsadmin client
Applying common configuration property changes
Enabling users to publish file attachments to Lotus Quickr
Configuring IBM HTTP Server for SSL
- Use the wsadmin client to access and check out the IBM Connections configuration files.
- Enter the following command to access the IBM Connections configuration file: execfile("connectionsConfig.py")
If prompted to specify a service to connect to, type 1 to pick the first node in the list. Most commands can run on any node. If the command writes or reads information to or from a file using a local file path, you must pick the node where the file is stored. This information is not used by the wsadmin client when you are making configuration changes.
- Enter the following command to check out the IBM Connections configuration files:
- working_directory is the temporary working directory to which the configuration XML and XSD files are copied and are stored while you make changes to them. Use forward slashes to separate directories in the file path, even if you are using the Microsoft® Windows® operating system.
AIX® and Linux® only: The directory must grant write permissions or the command does not run successfully.
- cell_name is the name of the WebSphere® Application Server cell hosting the IBM Connections application. This argument is case-sensitive, so type it with care. If you do not know the cell name, type the following command while in the wsadmin command processor:print AdminControl.getCell()
- AIX or Linux:LCConfigService.checkOutConfig("/opt/temp","foo01Cell01")
- Microsoft Windows:LCConfigService.checkOutConfig("c:/temp","foo01Cell01")
- Enter the following command:
- After making changes, you must check the configuration files back in and you must do so during the same wsadmin session in which you checked them out for the changes to take effect. See Applying common configuration property changes for information about how to save and apply your changes.
- Optional: To secure session cookies, complete the following steps:
- Log in to the WebSphere Application Server Integrated Solutions Console of the server hosting your IBM Connections applications as the administrator.
- Expand Servers -> Server Types, and then select WebSphere application servers.
- Click the server hosting IBM Connections from the list of server names.
- Click Session Management, and then click Enable cookies.
- Select the Restrict cookies to HTTPS sessions check box.
- Click Apply, and then click OK.
- Optional: To secure LTPA tokens, complete the following steps:
- From the WebSphere Application Server Integrated Solutions Console, expand Security, and then click Global security.
- Expand Web and SIP security, and then click single sign-on (SSO).
- Select the Requires SSL check box.
- Click Apply, and then click OK.