Manage LTPA keys from multiple WAS cells

 

+

Search Tips   |   Advanced Search

 

Overview

You can specify the shared keys and configure the authentication mechanism that is used to exchange information between servers to import and export LTPA keys across multiple WAS cells.

You must be sure that the exported key file for the multiple cells is accessible on the host where WAS is running. Also, know the password that was used when the keys were exported.

At runtime, the default key sets are CellLTPASecret and CellLTPAKeyPair. The default key group is CellLTPAKeySetGroup. After generation, keys are stored in the default key store CellLTPAKeys.

Complete the following steps to manage LTPA keys using the console.

 

Procedure

  1. Access the console.

  2. Verify that all of the WAS processes are running, including cells, nodes, and all of the appservers.

    If any of the servers are down at the time of key generation and then brought back up later, these servers might contain old keys. Copy the new set of keys to these servers, then bring them back up.

  3. Click...

    Security | Secure administration, applications, and infrastructure | Authentication mechanisms and expiration

  4. Type the password for the LTPA keys in the Password field.

    Enter a password that is used to encrypt and decrypt the LTPA keys from the SSO properties file. During import, this password should match the password that is used to export the keys at another LTPA server.

    During export, remember this password in order to provide it during the import operation.

  5. Type the password again in the Confirm password field.

  6. Select from among the following options:

  7. Start the server again for any changes you make to become active.

 

Results

The shared LTPA keys are now available for WebSphere Application Server to use for secure connections.

 

What to do next

After the keys are generated or imported, they are used to encrypt and decrypt the LTPA token. To view the latest key version, see Activating LTPA key versions.



LTPA key sets and key set groups

 

Related tasks


Exporting LTPA keys
Importing LTPA keys
Disabling automatic generation of LTPA keys
Activating LTPA key versions