Delete SPNEGO TAI properties using the wsadmin utility (deprecated)
You use the wsadmin utility to delete properties in the configuration of the SPNEGO trust association interceptor (TAI) for WAS.
In WAS Version 6.1, a TAI that uses the SPNEGO to securely negotiate and authenticate HTTP requests for secured resources was introduced. In WAS 7.0, this function is now deprecated. SPNEGO Web authentication has taken its place to provide dynamic reload of the SPNEGO filters and to enable fallback to the application login method. depfeat
Verify that end-user desktop browsers are configured to support SPNEGO authentication, that the SPNEGO TAI is enabled, that the JVM property is set and, that WAS is configured to enable the operation of the SPNEGO TAI. You use the wsadmin utility to configure the SPNEGO TAI for WAS:
- Start WAS.
- Start the command-line utility by running the wsadmin command from the APP_ROOT/bin directory.
- At the wsadmin prompt...
$AdminTask deleteSpnegoTAIPropertiesYou can use the following parameters with this command:
Option Description <spnId> This is an optional parameter. It is the SPN identifier for the group of custom properties that are to be deleted with this command. If we do not specify this parameter, all SPNEGO TAI custom properties are deleted.
Results
SPNEGO TAI properties are deleted for this WAS.
Example
- Example 1
The following example deletes all the SPNEGO TAI properties for SPN2
wsadmin>$AdminTask deleteSpnegoTAIProperties {-spnId 2}- Example 2
The following example deletes all SPNEGO TAI properties
wsadmin>$AdminTask deleteSpnegoTAIProperties com.ibm.ws.security.spnego.SPN1.filter=request-url!=noSPNEGO;request-url%=snoop com.ibm.ws.security.spnego.SPN1.hostName=central01.mpls.setgetweb.com com.ibm.ws.security.spnego.SPN2.hostName=wssecpd.mpls.setgetweb.com wsadmin>
Related tasks
Set WAS and enabling the SPNEGO TAI (deprecated)
Related
SPNEGO TAI custom properties configuration (deprecated)