Symptom:
If you enable SSL for the connection to the Federation Manager UI, the UI is still accessible over a non-SSL (HTTP) connection, potentially exposing an administrator's credentials.
Solution:
Enable the UI SSL port then disable the UI HTTP port.
To enable SSL for the UI
Note: You can skip this step if these ports were already defined when you first installed and configured Federation Manager.
The SSL Configuration dialog displays.
By clicking this button, SSL is enabled to protect the UI.
To disable the HTTP UI Port
Use the Federation Manager stop and start shortcuts as follows. If you logged in as a network user and not a local administrator, right-click the shortcut and select Run as administrator.
a. Open a command window.
b. Run the following scripts:
federation_mgr_home/fedmanager.sh stop
federation_mgr_home/fedmanager.sh start
When you run the fedmanager.sh script, it sources the Federation Manager environment script, ca_federation_env.ksh.
Note: Do not stop and start the services as the root user.
| Copyright © 2011 CA. All rights reserved. | Email CA Technologies about this topic |