Previous Topic: Uninstall the SiteMinder WSS AgentNext Topic: How to Configure Agents and Register a System as a Trusted Host


Install the SiteMinder WSS Agent for WebSphere on a UNIX System

This section contains the following topics:

Set the JRE in the PATH Variable

Apply the Unlimited Cryptography Patch to the JRE for SiteMinder WSS Agents

Configure the JVM to Use the JSafeJCE Security Provider

Run the Installer to Install a SiteMinder WSS Agent Using a GUI

Run the Installer to Install a SiteMinder WSS Agent Using a UNIX Console

Install a SiteMinder WSS Agent Using the Unattended Installer

Copy cryptojFIPS.jar to the WebSphere JRE

Installation and Configuration Log Files

How to Configure Agents and Register a System as a Trusted Host

Uninstall the SiteMinder WSS Agent

Set the JRE in the PATH Variable

Set the Java Runtime Environment (JRE) in the UNIX system PATH variable.

To set the JRE in the PATH variable

  1. Open a Command Window.
  2. Run the following commands:
    PATH=$PATH:JRE
    export PATH
    
    JRE

    Defines the location of your Java Runtime Environment bin directory.

Apply the Unlimited Cryptography Patch to the JRE for SiteMinder WSS Agents

Patch the Java Runtime Environment (JRE) used by the SiteMinder WSS Agent to support unlimited key strength in the Java Cryptography Extension (JCE) package.

The WebSphere JRE is based on Sun's JRE on the Solaris platform; this patch is available at Sun's website. The patch for other platforms is available at IBM's website. See the IBM documentation for more details.

The files that need to be patched are:

The local_policy.jar and US_export_policy.jar files can found be in the following locations:

Configure the JVM to Use the JSafeJCE Security Provider

The SiteMinder WSS Agent XML encryption function requires that the JVM is configured to use the JSafeJCE security provider.

Follow these steps:

  1. Add a security provider entry for JSafeJCE (com.rsa.jsafe.provider.JsafeJCE) to the java.security file located in the following location:
    JVM_HOME

    Is the installed location of the JVM used by the application server.

    In the following example, the JSafeJCE security provider entry has been added as the second security provider:

    security.provider.1=sun.security.provider.Sun
    security.provider.2=com.rsa.jsafe.provider.JsafeJCE
    security.provider.3=sun.security.rsa.SunRsaSign
    security.provider.4=com.sun.net.ssl.internal.ssl.Provider
    security.provider.5=com.sun.crypto.provider.SunJCE
    security.provider.6=sun.security.jgss.SunProvider
    security.provider.7=com.sun.security.sasl.Provider
    

    Note: If using the IBM JRE, always configure the JSafeJCE security provider immediately after (that is with a security provider number one higher than) the IBMJCE security provider (com.ibm.crypto.provider.IBMJCE)

  2. Add the following line to JVM_HOME\jre\lib\security\java.security (Windows) or JVM_HOME/jre/lib/security/java.security (UNIX) to set the initial FIPS mode of the JsafeJCE security provider:
    com.rsa.cryptoj.fips140initialmode=NON_FIPS140_MODE
    

    Note: The initial FIPS mode does not affect the final FIPS mode you select for the SiteMinder WSS Agent.

Run the Installer to Install a SiteMinder WSS Agent Using a GUI

Install the SiteMinder WSS Agent using the CA SiteMinder® Web Services Security installation media on the Technical Support site. Consider the following:

Follow these steps:

  1. Exit all applications that are running.
  2. Open a shell and navigate to where the install program is located.
  3. Enter the following command:
    ./ca-sm-wss-12.52-cr-unix_version.bin
    

    The CA SiteMinder® Web Services Security installer starts.

  4. Use gathered system and component information to install the SiteMinder WSS Agent. Consider the following when running the installer:
  5. Review the information presented on the Pre-Installation Summary page, then click Install.

    Note: If the installation program detects that newer versions of certain system libraries are installed on your system it asks if you want to overwrite these newer files with older files. Select No To All if you see this message.

    The SiteMinder WSS Agent files are copied to the specified location. Afterward, the CA SiteMinder® Web Services Security Configuration screen is displayed.

  6. Select one of the following options:
  7. Click Done.

    If you selected the option to configure SiteMinder WSS Agents now, the installation program prepares the CA SiteMinder® Web Services Security Configuration Wizard and begins the trusted host registration and configuration process.

    If you did not select the option to configure SiteMinder WSS Agents now or if you are required to reboot the system after installation you must start the configuration wizard manually later.

Installation Notes:

More information:

How to Configure Agents and Register a System as a Trusted Host

Run the Installer to Install a SiteMinder WSS Agent Using a UNIX Console

Install the SiteMinder WSS Agent using the CA SiteMinder® Web Services Security installation media on the Technical Support site. Consider the following:

Follow these steps:

  1. Exit all applications that are running.
  2. Open a shell and navigate to where the install program is located.
  3. Enter the following command:
    ./ca-sm-wss-12.52-cr-unix_version.bin -i console
    

    The CA SiteMinder® Web Services Security installer starts.

  4. Use gathered system and component information to install the SiteMinder WSS Agent. Consider the following as you make your selections:
  5. Review the information presented on the Pre-Installation Summary page, then proceed.

    Note: If the installation program detects that newer versions of certain system libraries are installed on your system it asks if you want to overwrite these newer files with older files. Select No To All if you see this message.

    The SiteMinder WSS Agent files are copied to the specified location. Afterward, the CA SiteMinder® Web Services Security Configuration screen is displayed.

  6. Select one of the following options:
  7. Hit Enter.

    If you selected the option to configure SiteMinder WSS Agents now, the installation program prepares the CA SiteMinder® Web Services Security Configuration Wizard and begins the trusted host registration and configuration process.

    If you did not select the option to configure SiteMinder WSS Agents now or if you are required to reboot the system after installation you must start the configuration wizard manually later.

Installation Notes:

More information:

How to Configure Agents and Register a System as a Trusted Host

Install a SiteMinder WSS Agent Using the Unattended Installer

After you have installed one or more SiteMinder WSS Agents on one machine, you can reinstall those agents on the same machine or install them with the same options on another machine using an unattended installation mode. An unattended installation lets you install or uninstall SiteMinder WSS Agents without any user interaction

The unattended installation uses the ca-wss-installer.properties file generated during the initial install from the information you specified to define the necessary installation parameters, passwords, paths, and so on.

The ca-wss-installer.properties file is located in: WSS_Home/install_config_info

WSS_Home

Specifies the path to where CA SiteMinder® Web Services Security is installed.

Default: C:\Program Files\CA\Web Services Security

To run the installer in the unattended installation mode

  1. From a system where CA SiteMinder® Web Services Security is already installed, copy the ca-wss-installer.properties file to a local directory on your system.
  2. Copy the SiteMinder WSS Agent installer file (ca-sm-wss-<SVMVER>-cr-unix_version) into the same local directory as the ca-wss-installer.properties file.
    cr

    Specifies the cumulative release number. The base 12.52 release does not include a cumulative release number.

    unix_version

    Specifies the UNIX version: sol or linux.

  3. Open a console window and navigate to the location where you copied the files.
  4. Run the following command:
    ./ca-sm-wss-<SVMVER>-cr-unix_version -f ca-wss-installer.properties -i silent
    

    The -i silent setting instructs the installer to run in the unattended installation mode.

    Note: If the ca-wss-installer.properties file is not in the same directory as the installation program, use double quotes if the argument contains spaces.

    Example:

    ./ca-sm-wss-<SVMVER>-cr-unix_version -f ~/CA/Web_Services_Security/install_config_info/ca-wss-installer.properties" -i silent
    

    An InstallAnywhere status bar appears, which shows that the unattended CA SiteMinder® Web Services Security installer has begun. The installer uses the parameters specified in the ca-wss-installer.properties file.

Installation Notes:

Copy cryptojFIPS.jar to the WebSphere JRE

If the installer displays a warning message stating that the cryptojFIPS.jar file is not present in the WebSphere JRE, you must manually copy the file into that location before you register the SiteMinder WSS Agent.

Copy cryptojFIPS.jar from the following location in the SiteMinder WSS Agent installation:

To the following location in the WebSphere installation:

Installation and Configuration Log Files

To check the results of the installation or review any specific problems during the installation or configuration of a SiteMinder WSS Agent, check the CA_SiteMinder_Web_Services_Security_Install_date-time_InstallLog.log file located in WSS_Home\install_config_info.

date-time

Specifies the date and time of the CA SiteMinder® Web Services Security installation.