security.xml
<?xml version="1.0" encoding="UTF-8"?> <security:Security xmi:version="2.0" xmlns:xmi="http://www.omg.org/XMI" xmlns:orb.securityprotocol="http://www.ibm.com/websphere/appserver/schemas/5.0/orb.securityprotocol.xmi" xmlns:security="http://www.ibm.com/websphere/appserver/schemas/5.0/security.xmi" xmi:id="Security_1" useLocalSecurityServer="true" useDomainQualifiedUserNames="false" enabled="true" cacheTimeout="600" issuePermissionWarning="true" activeProtocol="BOTH" enforceJava2Security="false" enforceFineGrainedJCASecurity="false" appEnabled="false" dynamicallyUpdateSSLConfig="true" activeAuthMechanism="LTPA_1" activeUserRegistry="WIMUserRegistry_1" defaultSSLSettings="SSLConfig_1"> <authMechanisms xmi:type="security:LTPA" xmi:id="LTPA_1" OID="oid:1.3.18.0.2.30.2" authContextImplClass="com.ibm.ISecurityLocalObjectTokenBaseImpl.WSSecurityContextLTPAImpl" authConfig="system.LTPA" simpleAuthConfig="system.LTPA" authValidationConfig="system.LTPA" timeout="120" keySetGroup="KeySetGroup_1"> <trustAssociation xmi:id="TrustAssociation_1" enabled="false"> <interceptors xmi:id="TAInterceptor_1" interceptorClassName="com.ibm.ws.security.web.WebSealTrustAssociationInterceptor"/> <interceptors xmi:id="TAInterceptor_2" interceptorClassName="com.ibm.ws.security.web.TAMTrustAssociationInterceptorPlus"/> <interceptors xmi:id="TAInterceptor_3" interceptorClassName="com.ibm.ws.security.spnego.TrustAssociationInterceptorImpl"/> <interceptors xmi:id="TAInterceptor_4" interceptorClassName="com.ibm.ws.sip.security.digest.DigestTAI"/> </trustAssociation> <singleSignon xmi:id="SingleSignon_1" requiresSSL="false" domainName="" enabled="true"/> </authMechanisms> <userRegistries xmi:type="security:LocalOSUserRegistry" xmi:id="LocalOSUserRegistry" serverId="" serverPassword="{xor}" realm="" useRegistryServerId="true" primaryAdminId=""/> <userRegistries xmi:type="security:CustomUserRegistry" xmi:id="CustomUserRegistry_1" useRegistryServerId="true" primaryAdminId="" customRegistryClassName="com.ibm.websphere.security.FileRegistrySample"/> <userRegistries xmi:type="security:LDAPUserRegistry" xmi:id="LDAPUserRegistry_1" serverId="" serverPassword="{xor}" realm="" ignoreCase="true" useRegistryServerId="true" primaryAdminId="" type="IBM_DIRECTORY_SERVER" sslEnabled="false" sslConfig="skyway2kCellManager01/DefaultSSLSettings" baseDN="" bindDN="" bindPassword="{xor}" searchTimeout="120" reuseConnection="true"> <searchFilter xmi:id="LDAPSearchFilter_1" userFilter="(&amp;(uid=%v)(objectclass=ePerson))" groupFilter="(&amp;(cn=%v)(|(objectclass=groupOfNames)(objectclass=groupOfUniqueNames)))" userIdMap="*:uid" groupIdMap="*:cn" groupMemberIdMap="ibm-allGroups:member;ibm-allGroups:uniqueMember" certificateMapMode="EXACT_DN" certificateFilter=""/> <hosts xmi:id="EndPoint_1" host="" port="389"/> </userRegistries> <userRegistries xmi:type="security:WIMUserRegistry" xmi:id="WIMUserRegistry_1" serverId="" serverPassword="{xor}" realm="defaultWIMFileBasedRealm" ignoreCase="true" useRegistryServerId="false" primaryAdminId="wasadmin" registryClassName="com.ibm.ws.wim.registry.WIMUserRegistry"/> <authConfig xmi:id="AuthorizationConfig_1" useJACCProvider="false"> <authorizationProviders xmi:id="AuthorizationProvider_1" j2eePolicyImplClassName="com.tivoli.pd.as.jacc.TAMPolicy" name="Tivoli Access Manager" policyConfigurationFactoryImplClassName="com.tivoli.pd.as.jacc.TAMPolicyConfigurationFactory" roleConfigurationFactoryImplClassName="com.tivoli.pd.as.jacc.TAMRoleConfigurationFactory" initializeJACCProviderClassName="com.tivoli.pd.as.jacc.cfg.TAMConfigInitialize" requiresEJBArgumentsPolicyContextHandler="false" supportsDynamicModuleUpdates="true"/> </authConfig> <applicationLoginConfig xmi:id="JAASConfiguration_1"> <entries xmi:id="JAASConfigurationEntry_1" alias="ClientContainer"> <loginModules xmi:id="JAASLoginModule_1" moduleClassName="com.ibm.ws.security.common.auth.module.proxy.WSLoginModuleProxy" authenticationStrategy="REQUIRED"> <options xmi:id="Property_1" name="delegate" value="com.ibm.ws.security.common.auth.module.WSClientLoginModuleImpl"/> </loginModules> </entries> <entries xmi:id="JAASConfigurationEntry_2" alias="WSLogin"> <loginModules xmi:id="JAASLoginModule_2" moduleClassName="com.ibm.ws.security.common.auth.module.proxy.WSLoginModuleProxy" authenticationStrategy="REQUIRED"> <options xmi:id="Property_2" name="delegate" value="com.ibm.ws.security.common.auth.module.WSLoginModuleImpl"/> <options xmi:id="Property_3" name="use_realm_callback" value="false"/> <options xmi:id="Property_4" name="use_appcontext_callback" value="false"/> </loginModules> </entries> <entries xmi:id="JAASConfigurationEntry_3" alias="DefaultPrincipalMapping"> <loginModules xmi:id="JAASLoginModule_3" moduleClassName="com.ibm.ws.security.common.auth.module.proxy.WSLoginModuleProxy" authenticationStrategy="REQUIRED"> <options xmi:id="Property_5" name="delegate" value="com.ibm.ws.security.auth.j2c.WSPrincipalMappingLoginModule"/> </loginModules> </entries> </applicationLoginConfig> <CSI xmi:id="IIOPSecurityProtocol_1"> <claims xmi:type="orb.securityprotocol:CommonSecureInterop" xmi:id="CSIv2 Inbound Configuration" stateful="true"> <layers xmi:type="orb.securityprotocol:IdentityAssertionLayer" xmi:id="IdentityAssertionLayer_1"> <supportedQOP xmi:type="orb.securityprotocol:IdentityAssertionQOP" xmi:id="IdentityAssertionQOP_1" enable="false"/> </layers> <layers xmi:type="orb.securityprotocol:MessageLayer" xmi:id="MessageLayer_1"> <requiredQOP xmi:type="orb.securityprotocol:MessageQOP" xmi:id="MessageQOP_2" establishTrustInClient="false"/> <supportedQOP xmi:type="orb.securityprotocol:MessageQOP" xmi:id="MessageQOP_1" establishTrustInClient="true"/> </layers> <layers xmi:type="orb.securityprotocol:TransportLayer" xmi:id="TransportLayer_1"> <requiredQOP xmi:type="orb.securityprotocol:TransportQOP" xmi:id="TransportQOP_2" establishTrustInClient="false" enableProtection="false" confidentiality="false" integrity="true"/> <supportedQOP xmi:type="orb.securityprotocol:TransportQOP" xmi:id="TransportQOP_1" establishTrustInClient="true" enableProtection="true" confidentiality="true" integrity="true"/> <serverAuthentication xmi:id="IIOPTransport_1" sslConfig=""/> </layers> </claims> <performs xmi:type="orb.securityprotocol:CommonSecureInterop" xmi:id="CSIv2 Outbound Configuration" stateful="true" sessionGCInterval="300000" sessionGCIdleTime="900000"> <layers xmi:type="orb.securityprotocol:IdentityAssertionLayer" xmi:id="IdentityAssertionLayer_2"> <requiredQOP xmi:type="orb.securityprotocol:IdentityAssertionQOP" xmi:id="IdentityAssertionQOP_3" enable="false"/> <supportedQOP xmi:type="orb.securityprotocol:IdentityAssertionQOP" xmi:id="IdentityAssertionQOP_2" enable="false" trustedId="" trustedPassword="{xor}"/> </layers> <layers xmi:type="orb.securityprotocol:MessageLayer" xmi:id="MessageLayer_2" authenticationLayerRetryCount="3"> <requiredQOP xmi:type="orb.securityprotocol:MessageQOP" xmi:id="MessageQOP_4" establishTrustInClient="false"/> <supportedQOP xmi:type="orb.securityprotocol:MessageQOP" xmi:id="MessageQOP_3" establishTrustInClient="true"/> </layers> <layers xmi:type="orb.securityprotocol:TransportLayer" xmi:id="TransportLayer_2"> <requiredQOP xmi:type="orb.securityprotocol:TransportQOP" xmi:id="TransportQOP_4" establishTrustInClient="false" enableProtection="false" confidentiality="false" integrity="true"/> <supportedQOP xmi:type="orb.securityprotocol:TransportQOP" xmi:id="TransportQOP_3" establishTrustInClient="false" enableProtection="true" confidentiality="true" integrity="true"/> <serverAuthentication xmi:id="IIOPTransport_2" sslConfig=""/> </layers> </performs> </CSI> <IBM xmi:id="IIOPSecurityProtocol_2"> <claims xmi:type="orb.securityprotocol:SecureAssociationService" xmi:id="SecureAssociationService_1"> <layers xmi:type="orb.securityprotocol:TransportLayer" xmi:id="TransportLayer_3"> <supportedQOP xmi:type="orb.securityprotocol:TransportQOP" xmi:id="TransportQOP_5" enableProtection="true" confidentiality="true" integrity="true"/> <serverAuthentication xmi:id="IIOPTransport_3" sslConfig=""/> </layers> </claims> <performs xmi:type="orb.securityprotocol:SecureAssociationService" xmi:id="SecureAssociationService_2"> <layers xmi:type="orb.securityprotocol:TransportLayer" xmi:id="TransportLayer_4"> <supportedQOP xmi:type="orb.securityprotocol:TransportQOP" xmi:id="TransportQOP_6" enableProtection="true" confidentiality="false" integrity="false"/> <serverAuthentication xmi:id="IIOPTransport_4" sslConfig=""/> </layers> </performs> </IBM> <repertoire xmi:id="SSLConfig_1" alias="CellDefaultSSLSettings" managementScope="ManagementScope_1"> <setting xmi:id="SecureSocketLayer_1" clientAuthentication="false" securityLevel="HIGH" enabledCiphers="" jsseProvider="IBMJSSE2" sslProtocol="SSL_TLS" keyStore="KeyStore_1" trustStore="KeyStore_2" trustManager="TrustManager_1" keyManager="KeyManager_1"/> </repertoire> <repertoire xmi:id="SSLConfig_2" alias="NodeDefaultSSLSettings" managementScope="ManagementScope_2"> <setting xmi:id="SecureSocketLayer_3" clientAuthentication="false" securityLevel="HIGH" enabledCiphers="" jsseProvider="IBMJSSE2" sslProtocol="SSL_TLS" keyStore="KeyStore_4" trustStore="KeyStore_2" trustManager="TrustManager_1" keyManager="KeyManager_1"/> </repertoire> <systemLoginConfig xmi:id="JAASConfiguration_2"> <entries xmi:id="JAASConfigurationEntry_4" alias="SWAM"> <loginModules xmi:id="JAASLoginModule_4" moduleClassName="com.ibm.ws.security.common.auth.module.proxy.WSLoginModuleProxy" authenticationStrategy="REQUIRED"> <options xmi:id="Property_8" name="delegate" value="com.ibm.ws.security.server.lm.swamLoginModule"/> </loginModules> </entries> <entries xmi:id="JAASConfigurationEntry_5" alias="LTPA"> <loginModules xmi:id="JAASLoginModule_5" moduleClassName="com.ibm.ws.security.common.auth.module.proxy.WSLoginModuleProxy" authenticationStrategy="REQUIRED"> <options xmi:id="Property_9" name="delegate" value="com.ibm.ws.security.server.lm.ltpaLoginModule"/> </loginModules> </entries> <entries xmi:id="JAASConfigurationEntry_6" alias="wssecurity.IDAssertion"> <loginModules xmi:id="JAASLoginModule_6" moduleClassName="com.ibm.ws.security.common.auth.module.proxy.WSLoginModuleProxy" authenticationStrategy="REQUIRED"> <options xmi:id="Property_10" name="delegate" value="com.ibm.wsspi.wssecurity.auth.module.IDAssertionLoginModule"/> </loginModules> </entries> <entries xmi:id="JAASConfigurationEntry_7" alias="wssecurity.Signature"> <loginModules xmi:id="JAASLoginModule_7" moduleClassName="com.ibm.ws.security.common.auth.module.proxy.WSLoginModuleProxy" authenticationStrategy="REQUIRED"> <options xmi:id="Property_11" name="delegate" value="com.ibm.wsspi.wssecurity.auth.module.SignatureLoginModule"/> </loginModules> </entries> <entries xmi:id="JAASConfigurationEntry_8" alias="LTPA_WEB"> <loginModules xmi:id="JAASLoginModule_8" moduleClassName="com.ibm.ws.security.common.auth.module.proxy.WSLoginModuleProxy" authenticationStrategy="REQUIRED"> <options xmi:id="Property_12" name="delegate" value="com.ibm.ws.security.web.AuthenLoginModule"/> </loginModules> </entries> <entries xmi:id="JAASConfigurationEntry_9" alias="WEB_INBOUND"> <loginModules xmi:id="JAASLoginModule_9" moduleClassName="com.ibm.ws.security.server.lm.ltpaLoginModule" authenticationStrategy="REQUIRED"/> <loginModules xmi:id="JAASLoginModule_10" moduleClassName="com.ibm.ws.security.server.lm.wsMapDefaultInboundLoginModule" authenticationStrategy="REQUIRED"/> </entries> <entries xmi:id="JAASConfigurationEntry_10" alias="RMI_INBOUND"> <loginModules xmi:id="JAASLoginModule_11" moduleClassName="com.ibm.ws.security.server.lm.ltpaLoginModule" authenticationStrategy="REQUIRED"/> <loginModules xmi:id="JAASLoginModule_12" moduleClassName="com.ibm.ws.security.server.lm.wsMapDefaultInboundLoginModule" authenticationStrategy="REQUIRED"/> </entries> <entries xmi:id="JAASConfigurationEntry_11" alias="DEFAULT"> <loginModules xmi:id="JAASLoginModule_13" moduleClassName="com.ibm.ws.security.server.lm.ltpaLoginModule" authenticationStrategy="REQUIRED"/> <loginModules xmi:id="JAASLoginModule_14" moduleClassName="com.ibm.ws.security.server.lm.wsMapDefaultInboundLoginModule" authenticationStrategy="REQUIRED"/> </entries> <entries xmi:id="JAASConfigurationEntry_12" alias="RMI_OUTBOUND"> <loginModules xmi:id="JAASLoginModule_15" moduleClassName="com.ibm.ws.security.server.lm.wsMapCSIv2OutboundLoginModule" authenticationStrategy="REQUIRED"/> </entries> <entries xmi:id="JAASConfigurationEntry_20" alias="wssecurity.X509BST"> <loginModules xmi:id="JAASLoginModule_20" moduleClassName="com.ibm.wsspi.wssecurity.auth.module.X509LoginModule" authenticationStrategy="REQUIRED"/> </entries> <entries xmi:id="JAASConfigurationEntry_21" alias="wssecurity.PkiPath"> <loginModules xmi:id="JAASLoginModule_21" moduleClassName="com.ibm.wsspi.wssecurity.auth.module.PkiPathLoginModule" authenticationStrategy="REQUIRED"/> </entries> <entries xmi:id="JAASConfigurationEntry_22" alias="wssecurity.PKCS7"> <loginModules xmi:id="JAASLoginModule_22" moduleClassName="com.ibm.wsspi.wssecurity.auth.module.PKCS7LoginModule" authenticationStrategy="REQUIRED"/> </entries> <entries xmi:id="JAASConfigurationEntry_23" alias="wssecurity.UsernameToken"> <loginModules xmi:id="JAASLoginModule_23" moduleClassName="com.ibm.wsspi.wssecurity.auth.module.UsernameLoginModule" authenticationStrategy="REQUIRED"/> </entries> <entries xmi:id="JAASConfigurationEntry_24" alias="wssecurity.IDAssertionUsernameToken"> <loginModules xmi:id="JAASLoginModule_24" moduleClassName="com.ibm.wsspi.wssecurity.auth.module.IDAssertionUsernameLoginModule" authenticationStrategy="REQUIRED"/> </entries> <entries xmi:id="JAASConfigurationEntry_25" alias="WSS_INBOUND"> <loginModules xmi:id="JAASLoginModule_26" moduleClassName="com.ibm.ws.security.server.lm.ltpaLoginModule" authenticationStrategy="REQUIRED"/> <loginModules xmi:id="JAASLoginModule_27" moduleClassName="com.ibm.ws.security.server.lm.wsMapDefaultInboundLoginModule" authenticationStrategy="REQUIRED"/> </entries> <entries xmi:id="JAASConfigurationEntry_28" alias="WSS_OUTBOUND"> <loginModules xmi:id="JAASLoginModule_29" moduleClassName="com.ibm.ws.security.server.lm.wsMapCSIv2OutboundLoginModule" authenticationStrategy="REQUIRED"/> </entries> </systemLoginConfig> <authDataEntries xmi:id="JAASAuthData_1183080691765" alias="skyway2kCell01/samples" userId="samples" password="{xor}by0+MTUrLWxs" description="JAAS Alias for WebSphere Samples"/> <properties xmi:id="Property_20" name="security.enablePluggableAuthentication" value="true" required="false"/> <properties xmi:id="Property_21" name="com.ibm.CSI.rmiOutboundPropagationEnabled" value="true" required="false"/> <properties xmi:id="Property_22" name="com.ibm.CSI.rmiInboundPropagationEnabled" value="true" required="false"/> <properties xmi:id="Property_23" name="com.ibm.CSI.rmiOutboundLoginEnabled" value="false" required="false"/> <properties xmi:id="Property_24" name="com.ibm.ws.security.webInboundPropagationEnabled" value="true" required="false"/> <properties xmi:id="Property_25" name="com.ibm.ws.security.ssoInteropModeEnabled" value="true" required="false"/> <properties xmi:id="Property_26" name="com.ibm.CSI.supportedTargetRealms" value="" required="false"/> <properties xmi:id="Property_27" name="com.ibm.CSI.rmiInboundLoginConfig" value="system.RMI_INBOUND" required="false"/> <properties xmi:id="Property_28" name="com.ibm.CSI.rmiOutboundLoginConfig" value="system.RMI_OUTBOUND" required="false"/> <properties xmi:id="Property_29" name="com.ibm.ws.security.webInboundLoginConfig" value="system.WEB_INBOUND" required="false"/> <properties xmi:id="Property_30" name="com.ibm.ws.security.defaultLoginConfig" value="system.DEFAULT" required="false"/> <properties xmi:id="Property_31" name="com.ibm.wsspi.security.ltpa.tokenFactory" value="com.ibm.ws.security.ltpa.LTPATokenFactory|com.ibm.ws.security.ltpa.LTPAToken2Factory|com.ibm.ws.security.ltpa.AuthzPropTokenFactory" required="false"/> <properties xmi:id="Property_32" name="com.ibm.wsspi.security.token.authenticationTokenFactory" value="com.ibm.ws.security.ltpa.LTPATokenFactory" required="false"/> <properties xmi:id="Property_33" name="com.ibm.wsspi.security.token.authorizationTokenFactory" value="com.ibm.ws.security.ltpa.AuthzPropTokenFactory" required="false"/> <properties xmi:id="Property_34" name="com.ibm.wsspi.security.token.propagationTokenFactory" value="com.ibm.ws.security.ltpa.AuthzPropTokenFactory" required="false"/> <properties xmi:id="Property_35" name="com.ibm.wsspi.security.token.singleSignonTokenFactory" value="com.ibm.ws.security.ltpa.LTPAToken2Factory" required="false"/> <properties xmi:id="Property_36" name="com.ibm.audit.auditServiceEnabled" value="false" required="false"/> <properties xmi:id="Property_37" name="com.ibm.audit.auditPolicy" value="REQUIRED" required="false"/> <properties xmi:id="Property_38" name="com.ibm.audit.auditQueueSize" value="5000" required="false"/> <properties xmi:id="Property_39" name="com.ibm.websphere.security.audit.auditEventFactory" value="J2EE=com.ibm.ws.security.audit.defaultAuditEventFactoryImpl" required="false"/> <properties xmi:id="Property_40" name="com.ibm.wsspi.security.audit.auditServiceProvider" value="DEFAULT=com.ibm.ws.security.audit.defaultAuditServiceProviderImpl" required="false"/> <properties xmi:id="Property_41" name="com.ibm.audit.auditSpecification" value="J2EE=AUTHN=failure=enabled:J2EE=AUTHZ=failure=enabled" required="false"/> <properties xmi:id="Property_42" name="com.ibm.ws.security.webChallengeIfCustomSubjectNotFound" value="true" required="false"/> <properties xmi:id="Property_43" name="com.ibm.security.useFIPS" value="false" required="false"/> <webAuthAttrs xmi:id="DescriptiveProperty_1" name="com.ibm.wsspi.security.web.webAuthReq" value="lazy" type="String" displayNameKey="" nlsRangeKey="" hoverHelpKey="" range="lazy,persisting,always" inclusive="false" firstClass="false"/> <webAuthAttrs xmi:id="DescriptiveProperty_2" name="com.ibm.wsspi.security.web.failOverToBasicAuth" value="false" type="boolean" displayNameKey="" nlsRangeKey="" hoverHelpKey="" range="" inclusive="false" firstClass="false"/> <managementScopes xmi:id="ManagementScope_1" scopeName="(cell):skyway2kCell01" scopeType="cell"/> <managementScopes xmi:id="ManagementScope_2" scopeName="(cell):skyway2kCell01:(node):skyway2kNode01" scopeType="node"/> <managementScopes xmi:id="ManagementScope_1184553106671" scopeName="(cell):skyway2kCell01:(node):skyway2kNode01:(server):webserver1" scopeType="server"/> <managementScopes xmi:id="ManagementScope_1184555175421" scopeName="(cell):skyway2kCell01:(node):skyway2kNode01:(server):webserverA" scopeType="server"/> <managementScopes xmi:id="ManagementScope_1184605646453" scopeName="(cell):skyway2kCell01:(node):HAARLEM-node:(server):webserver2" scopeType="server"/> <managementScopes xmi:id="ManagementScope_1184628440578" scopeName="(cell):skyway2kCell01:(node):HAARLEM-node:(server):webserver4" scopeType="server"/> <keyStores xmi:id="KeyStore_1" name="CellDefaultKeyStore" password="{xor}CDo9Hgw=" provider="IBMJCE" location="${CONFIG_ROOT}/cells/skyway2kCell01/key.p12" type="PKCS12" fileBased="true" hostList="" managementScope="ManagementScope_1"/> <keyStores xmi:id="KeyStore_2" name="CellDefaultTrustStore" password="{xor}CDo9Hgw=" provider="IBMJCE" location="${CONFIG_ROOT}/cells/skyway2kCell01/trust.p12" type="PKCS12" fileBased="true" hostList="" managementScope="ManagementScope_1"/> <keyStores xmi:id="KeyStore_3" name="CellLTPAKeys" password="{xor}CDo9Hgw=" provider="IBMJCE" location="${CONFIG_ROOT}/cells/skyway2kCell01/ltpa.jceks" type="JCEKS" fileBased="true" hostList="" managementScope="ManagementScope_1"/> <keyStores xmi:id="KeyStore_4" name="NodeDefaultKeyStore" password="{xor}CDo9Hgw=" provider="IBMJCE" location="${CONFIG_ROOT}/cells/skyway2kCell01/nodes/skyway2kNode01/key.p12" type="PKCS12" fileBased="true" hostList="" managementScope="ManagementScope_2"/> <keyStores xmi:id="KeyStore_5" name="NodeDefaultTrustStore" password="{xor}CDo9Hgw=" provider="IBMJCE" location="${CONFIG_ROOT}/cells/skyway2kCell01/nodes/skyway2kNode01/trust.p12" type="PKCS12" fileBased="true" hostList="" managementScope="ManagementScope_2"/> <keyStores xmi:id="KeyStore_1184562700078" name="CMSKeyStore" password="{xor}CDo9Hgw=" provider="IBMCMSProvider" location="C:\IBM\WAS61\AppServer\profiles\Dmgr01\config/cells/skyway2kCell01/nodes/skyway2kNode01/servers/webserverA/plugin-key.kdb" type="CMSKS" fileBased="true" createStashFileForCMS="true" managementScope="ManagementScope_1184555175421"/> <keyStores xmi:id="KeyStore_1184628440640" name="CMSKeyStore" password="{xor}CDo9Hgw=" provider="IBMCMSProvider" location="C:\IBM\WAS61\AppServer\profiles\Dmgr01\config/cells/skyway2kCell01/nodes/HAARLEM-node/servers/webserver4/plugin-key.kdb" type="CMSKS" fileBased="true" createStashFileForCMS="true" managementScope="ManagementScope_1184628440578"/> <trustManagers xmi:id="TrustManager_1" name="IbmX509" provider="IBMJSSE2" algorithm="IbmX509" managementScope="ManagementScope_1"/> <trustManagers xmi:id="TrustManager_2" name="IbmPKIX" provider="IBMJSSE2" algorithm="IbmPKIX" trustManagerClass="" managementScope="ManagementScope_1"> <additionalTrustManagerAttrs xmi:id="DescriptiveProperty_1" name="com.ibm.security.enableCRLDP" value="true" type="boolean" displayNameKey="" nlsRangeKey="" hoverHelpKey="" range="" inclusive="false" firstClass="false"/> <additionalTrustManagerAttrs xmi:id="DescriptiveProperty_2" name="com.ibm.jsse2.checkRevocation" value="true" type="boolean" displayNameKey="" nlsRangeKey="" hoverHelpKey="" range="" inclusive="false" firstClass="false"/> </trustManagers> <keyManagers xmi:id="KeyManager_1" name="IbmX509" provider="IBMJSSE2" algorithm="IbmX509" keyManagerClass="" managementScope="ManagementScope_1"/> <keySetGroups xmi:id="KeySetGroup_1" name="CellLTPAKeySetGroup" autoGenerate="true" wsSchedule="WSSchedule_1" keySet="KeySet_1 KeySet_2" managementScope="ManagementScope_1"/> <keySets xmi:id="KeySet_1" name="CellLTPAKeyPair" aliasPrefix="LTPAKeyPair" password="{xor}CDo9Hgw=" maxKeyReferences="2" deleteOldKeys="true" keyGenerationClass="com.ibm.ws.security.ltpa.LTPAKeyPairGenerator" isKeyPair="true" keyStore="KeyStore_3" managementScope="ManagementScope_1"> <keyReference xmi:id="KeyReference_1" keyAlias="LTPAKeyPair_1" version="1"/> <keyReference xmi:id="KeyReference_1199848480890" keyAlias="LTPAKeyPair_2" version="2"/> </keySets> <keySets xmi:id="KeySet_2" name="CellLTPASecret" aliasPrefix="LTPASecret" password="{xor}CDo9Hgw=" maxKeyReferences="2" keyGenerationClass="com.ibm.ws.security.ltpa.LTPAKeyGenerator" keyStore="KeyStore_3" managementScope="ManagementScope_1"> <keyReference xmi:id="KeyReference_2" keyAlias="LTPASecret_1" version="1"/> <keyReference xmi:id="KeyReference_1199848490000" keyAlias="LTPASecret_2" version="2"/> </keySets> <wsSchedules xmi:id="WSSchedule_1" name="LTPAKeySetSchedule" frequency="90" dayOfWeek="1" hour="22" nextStartDate="1214794851343"/> <wsSchedules xmi:id="WSSchedule_2" name="ExpirationMonitorSchedule" frequency="30" dayOfWeek="1" hour="21" minute="30" nextStartDate="1209349801250"/> <wsNotifications xmi:id="WSNotification_1" name="MessageLog" logToSystemOut="true" emailList=""/> <wsCertificateExpirationMonitor xmi:id="WSCertificateExpirationMonitor_1" name="Certificate Expiration Monitor" autoReplace="true" deleteOld="true" daysBeforeNotification="60" isEnabled="true" wsNotification="WSNotification_1" wsSchedule="WSSchedule_2"/> <sslConfigGroups xmi:id="SSLConfigGroup_1" name="skyway2kCell01" direction="inbound" sslConfig="SSLConfig_1" managementScope="ManagementScope_1"/> <sslConfigGroups xmi:id="SSLConfigGroup_2" name="skyway2kCell01" direction="outbound" sslConfig="SSLConfig_1" managementScope="ManagementScope_1"/> <sslConfigGroups xmi:id="SSLConfigGroup_3" name="skyway2kNode01" direction="inbound" sslConfig="SSLConfig_2" managementScope="ManagementScope_2"/> <sslConfigGroups xmi:id="SSLConfigGroup_4" name="skyway2kNode01" direction="outbound" sslConfig="SSLConfig_2" managementScope="ManagementScope_2"/> </security:Security>