If your Policy Server is part of an implementation that includes multiple key stores, you can manually enter the session ticket key.
To enter the session ticket key
The Key Management pane opens.
Enter a session ticket key
Re-enter the session ticket key
The Policy Server immediately replaces the existing session ticket key with the value you entered.
When a single Policy Server generates encryption keys in an environment with multiple Policy Servers that connect to disparate policy stores, but share a central key store, an additional registry setting is required. This registry setting configures each Policy Server to poll the common key store and retrieve new encryption keys at a regular interval.
To configure the EnableKeyUpdate registry key on a Windows Policy Server
HKEY_LOCAL_MACHINE\SOFTWARE\Netegrity\SiteMinder\ CurrentVersion\ObjectStore
"EnableKeyUpdate"=0
to
"EnableKeyUpdate"=1
To configure the EnableKeyUpdate registry key on a UNIX Policy Server
install_directory/siteminder/registry
HKEY_LOCAL_MACHINE\SOFTWARE\Netegrity\SiteMinder\ CurrentVersion\ObjectStore
"EnableKeyUpdate"=0
to
"EnableKeyUpdate"=1
Copyright © 2012 CA.
All rights reserved.
|
|