IBM BS029ML Self Help Guide - Page 31

Logical Deployment Units, Internet Browser, Tivoli WebSEAL, Tivoli Access Manager Policy Server

Page 31 highlights

aspects of a solution architecture. By contrast, the operational model provides the description and configuration of the hardware and software technologies needed to deliver the required solution characteristics and capabilities, within the constraints of technology, skills, and budget. It describes the distribution of the solution components onto geographically distributed nodes, together with the connections necessary to achieve the solution functional and non-functional requirements. Typically, the development of both the component and operational models follow various recognized paths using standard techniques or approaches. However, with the advent of Commercially-Off-The-Shelf (COTS) packages, such as WebSphere Portal Server, the demands on the IT Architect and Portal Practitioner have been reduced. Nevertheless, our experience tells that making mistakes during the architectural phase of an implemention can lead to major consequences later on in a project. As such, it is strongly recommended that IBM is engaged during this crucial period of any implementation, if not at any other time during a project. 2.2.1 Logical Deployment Units The following Deployment Units are considered in regards to a WebSphere Portal Server architecture. The list, however, is by no means exhaustive and provides only a starting point in recognizing the primary Commercially-Off-The-Shelf (COTS) packages associated with such an architecture. Internet Browser The Internet Browser component is a standard Web browser, such as Internet Explorer® or Mozilla Firefox. This component communicates with the solution through the HTTP / HTTPS protocol, receives responses in HTML format, and renders them for the user. The Internet Browser has general characteristics that include Graphical Presentation, HTML, Applet Execution within a Java Virtual Machine (JVM™), JavaScript™ Execution, Plug-In Support, Caching, Security and encryption Services, and Content Persistence (cookies). Tivoli WebSEAL (Optional) Tivoli WebSEAL is a high-performance, multi-threaded Web Proxy server that applies fine-grained security policy to the Tivoli Access Manager protected Web object space. WebSEAL can provide single sign-on solutions and incorporate back-end Web application server resources into its security policy. WebSEAL normally acts as a reverse Web proxy by receiving HTTP/HTTPS requests from a Web browser and delivering content from its own Web server or from junctioned back-end Web application servers. Requests passing through WebSEAL are evaluated by the Tivoli Access Manager authorization service to determine whether the user is authorized to access the requested resource. Tivoli Access Manager Policy Server (Optional) The Tivoli Access Manager Policy Server for e-business is an authorization and management solution that scales across the entire enterprise. A robust and secure policy management tool for e-business and distributed applications, it addresses the challenges of escalating security costs, growing complexity, and the need for uniform security policies across platforms. Tivoli Access Manager unites core security technologies around common security policies to help reduce implementation time and management complexity, thereby lowering the total cost of security-enhanced computing. Chapter 2. Architecture and planning 17

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242

Chapter 2. Architecture and planning
17
aspects of a solution architecture. By contrast, the operational model provides the description
and configuration of the hardware and software technologies needed to deliver the required
solution characteristics and capabilities, within the constraints of technology, skills, and
budget. It describes the distribution of the solution components onto geographically
distributed nodes, together with the connections necessary to achieve the solution functional
and non-functional requirements.
Typically, the development of both the component and operational models follow various
recognized paths using standard techniques or approaches. However, with the advent of
Commercially-Off-The-Shelf (COTS) packages, such as WebSphere Portal Server, the
demands on the IT Architect and Portal Practitioner have been reduced. Nevertheless, our
experience tells that making mistakes during the architectural phase of an implemention can
lead to major consequences later on in a project. As such, it is strongly recommended that
IBM is engaged during this crucial period of any implementation, if not at any other time
during a project.
2.2.1
Logical Deployment Units
The following Deployment Units are considered in regards to a WebSphere Portal Server
architecture. The list, however, is by no means exhaustive and provides only a starting point
in recognizing the primary Commercially-Off-The-Shelf (COTS) packages associated with
such an architecture.
Internet Browser
The Internet Browser component is a standard Web browser, such as Internet Explorer® or
Mozilla Firefox. This component communicates with the solution through the HTTP / HTTPS
protocol, receives responses in HTML format, and renders them for the user. The Internet
Browser has general characteristics that include Graphical Presentation, HTML, Applet
Execution within a Java Virtual Machine (JVM™), JavaScript™ Execution, Plug-In Support,
Caching, Security and encryption Services, and Content Persistence (cookies).
Tivoli WebSEAL
(Optional)
Tivoli WebSEAL is a high-performance, multi-threaded Web Proxy server that applies
fine-grained security policy to the Tivoli Access Manager protected Web object space.
WebSEAL can provide single sign-on solutions and incorporate back-end Web application
server resources into its security policy. WebSEAL normally acts as a reverse Web proxy by
receiving HTTP/HTTPS requests from a Web browser and delivering content from its own
Web server or from junctioned back-end Web application servers. Requests passing through
WebSEAL are evaluated by the Tivoli Access Manager authorization service to determine
whether the user is authorized to access the requested resource.
Tivoli Access Manager Policy Server
(Optional)
The Tivoli Access Manager Policy Server for e-business is an authorization and management
solution that scales across the entire enterprise. A robust and secure policy management tool
for e-business and distributed applications, it addresses the challenges of escalating security
costs, growing complexity, and the need for uniform security policies across platforms. Tivoli
Access Manager unites core security technologies around common security policies to help
reduce implementation time and management complexity, thereby lowering the total cost of
security-enhanced computing.