Configuring failover authentication

You can configure WebSEAL for failover authentication.

About this task

To configure failover authentication, complete the following tasks:
Note:

For more information about the configuration entries that are related to these tasks, see the Web Reverse Proxy Stanza Reference topics in the IBM Knowledge Center.

Procedure

  1. Stop the WebSEAL server.
  2. To enable failover authentication, complete each of the following tasks:
    1. Protocol for failover cookies
    2. Generating a key pair to encrypt and decrypt cookie data
    3. Specifying the failover cookie lifetime
    4. Specifying UTF-8 encoding on cookie strings
    5. Adding the authentication strength level
    6. Reissue of missing failover cookies
  3. Optionally, you can configure WebSEAL to maintain session state across failover authentication sessions. If this configuration is appropriate for your deployment, complete the following instructions:
    1. Addition of session lifetime timestamp
    2. Adding the session activity timestamp
    3. Addition of an interval for updating the activity timestamp
  4. Optionally, you can configure WebSEAL to add extended attributes to the failover cookie:
  5. When WebSEAL is configured to add attributes to the failover cookie, you must configure WebSEAL to extract the attributes when reading the cookie:
  6. Optionally, you can enable failover authentication cookies for use on any WebSEAL server in the domain. If this configuration is appropriate for your deployment, see:
  7. To maintain compatibility with failover authentication cookies generated by WebSEAL servers from versions before version 8.0, complete the instructions in Enabling compatibility for failover cookies.
  8. To maintain compatibility with failover authentication cookies generated by WebSEAL servers from versions before version 6.0, complete the following instructions:
    1. Specifying UTF-8 encoding on cookie strings
    2. Validation of a lifetime timestamp
    3. Validation of an activity timestamp
  9. After completing all the instructions applicable to your deployment, restart the WebSEAL server.