SPNEGO Web authentication enablement

You can enable the Simple and Protected GSS-API Negotiation (SPNEGO) as the Web Authenticator for WebSphere® Application Server.

SPNEGO Web authentication provides client-server single sign-on by negotiating use of SPNEGO tokens.

To view this administrative console page, click Security > Global security. From Authentication, expand Web and SIP Security, and then click SPNEGO Web authentication.

Dynamically update SPNEGO

Enables you to dynamically update the SPNEGO runtime when SPNEGO changes occur without restarting the application server.

Note: This option is disabled if the Enable SPNEGO option is not selected.
Default: Enabled

Enable SPNEGO

Specifies the Simple and Protected GSS-API Negotiation Mechanism (SPNEGO) as a Web Authenticator for the application server.

Default: Disabled

Allow fall back to application authentication mechanism

Specifies that SPNEGO as a Web authenticator is used to log in to WebSphere Application Server first. However, if the login fails, then the application authentication mechanism is used to log in to WebSphere Application Server.

Note: This option is disabled if the Enable SPNEGO option is not selected.
Default: Disabled

Kerberos configuration file with full path

The Kerberos configuration file name with its full path. You can click Browse to locate it.

The Kerberos client configuration file, krb5.conf or krb5.ini, contains Kerberos configuration information, including the locations of the Key Distribution Centers (KDCs) for the realm of interest. The krb5.conf file is the default name for all platforms except the Windows operating system, which uses the krb5.ini file.

Data type: String

Kerberos keytab file name with full path

The Kerberos keytab file name with its full path. You can click Browse to locate it.

The Kerberos keytab file contains one or more Kerberos service principal names and keys. The default keytab file is krb5.keytab. It is important for hosts to protect their Kerberos keytab files by storing them on the local disk, which makes them readable only by authorized users. Read about Creating a Kerberos service principal and keytab file for more information.

If you do not specify a Kerberos keytab file then the default keytab file that is defined in the Kerberos configuration file is used.

Data type: String



Related reference
SPNEGO Web authentication filter values
Kerberos authentication
Reference topic    

Terms of Use | Feedback

Last updated: Oct 22, 2010 12:21:29 AM CDT
http://www14.software.ibm.com/webapp/wsbroker/redirect?version=compass&product=was-nd-zos&topic=usec_kerb_SPNEGO_config
File name: usec_kerb_SPNEGO_config.html