Configure failover authentication

We can configure WebSEAL for failover authentication.

To configure failover authentication, complete the following tasks:

For information about the configuration entries related to these tasks, see the web reverse proxy Stanza Reference topics in the IBM Knowledge Center.

Steps

  1. Stop the WebSEAL server.

  2. To enable failover authentication, complete each of the following tasks:

    1. Protocol for failover cookies
    2. Generating a key pair to encrypt and decrypt cookie data
    3. Specify the failover cookie lifetime
    4. Specify UTF-8 encoding on cookie strings
    5. Add the authentication strength level
    6. Reissue of missing failover cookies

  3. Optionally, we can configure WebSEAL to maintain session state across failover authentication sessions. If this configuration is appropriate for your deployment, complete the following instructions:

    1. Addition of session lifetime timestamp
    2. Add the session activity timestamp
    3. Addition of an interval for updating the activity timestamp

  4. Optionally, we can configure WebSEAL to add extended attributes to the failover cookie:

  5. When WebSEAL is configured to add attributes to the failover cookie, configure WebSEAL to extract the attributes when reading the cookie:

  6. Optionally, we can enable failover authentication cookies for use on any WebSEAL server in the domain. If this configuration is appropriate for your deployment, see:

  7. To maintain compatibility with failover authentication cookies generated by WebSEAL servers from versions before version 8.0, complete the instructions in Enable compatibility for failover cookies.

  8. To maintain compatibility with failover authentication cookies generated by WebSEAL servers from versions before version 6.0, complete the following instructions:

    1. Specify UTF-8 encoding on cookie strings
    2. Validation of a lifetime timestamp
    3. Validation of an activity timestamp

  9. After completing all the instructions applicable to your deployment, restart the WebSEAL server.

Parent topic: Failover authentication configuration