server task virtualhost add

The server task virtualhost add command adds an additional installed WebSEAL server or instance to an existing virtual host junction.

Requires authentication (administrator ID and password) to use this command.

Syntax

server task instance_name-webseald-host_name virtualhost add –h host_name [options] vhost_label

Options

instance_name-webseald-host_name
Specifies the full server name of the installed WebSEAL instance. You must specify this full server name in the exact format as displayed in the output of the server list command.

The instance_name specifies the configured name of the WebSEAL instance. The webseald designation indicates that the WebSEAL service performs the command task. The host_name is the name of the physical machine where the WebSEAL server is installed.

For example, if the configured name of a single WebSEAL instance is default, and host machine name where the WebSEAL server is installed is abc.ibm.com, the full WebSEAL server name is default-webseald-abc.ibm.com.

If an additional WebSEAL instance is configured and named web2, the full WebSEAL server name is web2-webseald-abc.ibm.com.

options
Specifies the options that you can use with the server task virtualhost add command. These options include:
–D "dn"
Specifies the distinguished name of the back-end server certificate. This value, matched with the actual certificate DN enhances authentication and provides mutual authentication over SSL. For example, the certificate for www.example.com might have a DN of
"CN=WWW.EXAMPLE.COM,OU=Software,O=example.com\, Inc,L=Austin,
ST=Texas,C=US"

This option is valid only with junctions that were created with the type of ssl or sslproxy.

–H host_name
Specifies the DNS host name or IP address of the proxy server.
Valid values for host_name include any valid IP host name. For example:
proxy.www.example.com

This option is used for junctions that were created with the type of tcpproxy or sslproxy.

–i
Indicates that the WebSEAL server does not treat URLs as case-sensitive.

This option is used for junctions that were created with the type of tcp or ssl.

–p port
Specifies the TCP port of the back-end server. The default value is 80 for TCP junctions and 443 for SSL junctions. This option is used for junctions that were created with the type of tcp or ssl.
–P port
Specifies the TCP port of the proxy server. The default value is 7138.

For port, use any valid port number. A valid port number is any positive number that is allowed by TCP/IP and that is not currently being used by another application. Use the default port number value, or use a port number that is greater then 1000 that is currently not being used.

This option is used for junctions that were created with the type of tcpproxy or sslproxy.

–q path
Required option for back-end Windows™ virtual hosts. Specifies the relative path for the query_contents script. By default, Verify Identity Access looks for this script in the /cgi_bin subdirectory. If this directory is different or the query_contents file is renamed, use this option to indicate to WebSEAL the new URL to the file.

This option is valid for all junction types except localtcp and localssl.

–u uuid
Specifies the UUID of this back-end server when connected to WebSEAL over a stateful junction that was using the –s option. This option is used for junctions that were created with the type of tcp or ssl.
–w
Indicates Microsoft™ Windows file system support.

This option is used for junctions that were created with the type of tcp or ssl.

vhost_label
Specifies the label name of the virtual host junction.
–h host_name
Required option. Specifies the DNS host name or IP address of the target server. Valid values for host_name include any valid IP host name. For example:
www.example.com

Authorization

Users and groups that require access to this command must be given the c (control) permission in the ACL that governs the /WebSEAL/host_name-instance_name/@vhost_label object. For example, the sec_master administrative user has permission by default.

Note: This command is available only when WebSEAL is installed.

Return codes

0
The command completed successfully. For WebSEAL server task commands, the return code will be 0 when the command is sent to the WebSEAL server without errors.
Note: Even if the command was successfully sent, the WebSEAL server might not be able to successfully complete the command and can return an error message.
1
The command failed. When a command fails, the pdadmin command provides a description of the error and an error status code in hexadecimal format (for example, 0x14c012f2). See "Error messages" in the IBM Knowledge Center which provides a list of the Verify Identity Access error messages by decimal or hexadecimal codes.

Examples

The following example (entered as one line) adds an additional server with host name xyz.ibm.com to an existing virtual host junction with the label support-vhost-http, located on the WebSEAL server abc.ibm.com:
pdadmin> server task default-webseald-abc.ibm.com virtualhost add 
-h xyz.ibm.com support-vhost-http

See also

server task virtualhost create
server task virtualhost delete
server task virtualhost list
server task virtualhost remove
server task virtualhost show