Configuring the agent occurs after the installation. Configuration requires several separate procedures which are described using the following process:
Gather the following information about the environment for the product before running the configuration program for the agent:
Indicates whether you want to register a trusted host. This registration creates a trusted host object in the Policy Server and an SmHost.conf file on the web server. The agent uses this information to make an initial connection to Policy Servers when it starts. Register each agent instance as a trusted host only once.
Default:Yes
Options: Yes, No
Specifies the name of a CA SiteMinder® user with Administrative privileges that is already defined in the Policy Server. This CA SiteMinder® user account requires privileges to register trusted hosts.
Specifies a password for the Admin User Name that is already defined in the Policy Server.
Repeats the password entered in the Admin Password field. This value verifies the password for the Admin User Name already defined in the Policy Server.
Specifies a unique name for the trusted host you are registering. This trusted host object is stored on the Policy Server.
Specifies the name of a Host Configuration Object that is already defined in the Policy Server. After the agent initially connects to a Policy Server (using the SmHost.conf file settings), subsequent connections use the settings from the Host Configuration Object.
Specifies the Internet Protocol address of the Policy Servers to which the agent attempts to connect upon startup. If your Policy Server is behind a firewall, specify a port number also.
If a hardware load balancer is configured to expose Policy Servers in your environment through a single Virtual IP Address (VIP), enter the VIP.
Example: (IPV4) 192.168.1.105
Example: (IPV4 with the port number) 192.168.1.105:44443
Example: (IPV6) 2001:DB8::/32
Example: (IPV6) [2001:DB8::/32]:44443
Specifies one of the following algorithms:
Uses algorithms existing in previous versions of CA SiteMinder® to encrypt sensitive data and is compatible with previous versions of CA SiteMinder®. If your organization does not require the use of FIPS-compliant algorithms, use this option.
Allows a transition from FIPS-compatibility mode to FIPS-only mode. In FIPS-migration mode, CA SiteMinder® environment continues to use existing CA SiteMinder® encryption algorithms as you reencrypt existing sensitive data using FIPS-compliant algorithms.
Uses only FIPS-compliant algorithms to encrypt sensitive data in the CA SiteMinder® environment. This setting does not interoperate with, nor is backwards-compatible with, previous versions of CA SiteMinder®.
Default: FIPS Compatibility/AES Compatibility
FIPS is a US government computer security standard that accredits cryptographic modules which meet the Advanced Encryption Standard (AES).
Important! Use a compatible FIPS/AES mode (or a combination of compatible modes) for both the CA SiteMinder® agent and the Policy Server.
Specifies the name of the SmHost.conf file which contains the settings the Web Agent uses to make initial connections to a Policy Server.
Specifies the directory where the SmHost.conf file is stored.
Default: web_agent_home\config
Select this check box to change the shared secret that the Policy Server uses to encrypt communications to the Web Agents.
This step has multiple screens. The first screen indicates the server type (Apache), and the next screen displays the web server instances that the configuration program finds on the computer. Select the check boxes of the server type, and the instances you want to configure. Clear the check boxes of those instances from which you want to remove CA SiteMinder® protection.
Specifies the location of the installation directory for your Apache-based server (version 2.4 or higher).
Specifies the name of an agent configuration object (ACO) already defined on the Policy Server.
Default: AgentObj
Specifies the advanced authentication scheme for the web server instances you selected previously.
After gathering the information for your agent configuration, run the agent configuration program. This program creates an agent runtime instance for the web servers running on your computer.
This configuration program is wizard or console based, depending on the option you select. Running the configuration program in the wizard or console mode once creates a properties file. Use the properties file to run unattended configurations on other computers with same operating environment in the future.
Follow these steps:
web_agent_home\install_config_info
Indicates the directory where the CA SiteMinder® agent is installed on your web server.
Default (Windows 32-bit installations only): C:\Program Files\CA\webagent
Default (Windows 64-bit installations only): C:\Program Files\CA\webagent\win64
Default (Windows 32-bit applications operating on 64-bit systems [Wow64]): C:\Program Files (x86)\webagent\win32
ca-wa-config.exe
-i console
The agent runtime instance is created for your web servers.
Copyright © 2015 CA Technologies.
All rights reserved.
|
|