【发布时间】:2018-11-28 17:02:47
【问题描述】:
我正在调查 Liberty 中“禁用”LTPA 事物的概念,并希望得到一些指导。我正在追求 2 个想法 - 首先,是否可以阻止 Liberty 服务器生成 LTPA 密钥?其次,是否可以阻止 Liberty 服务器向客户端浏览器发送 LTPA 令牌/cookie?
在发表这篇文章之前,我浏览了 Liberty 文档。 Liberty KC https://www.ibm.com/support/knowledgecenter/en/SSEQTP_liberty/com.ibm.websphere.wlp.doc/ae/twlp_sec_ltpa.html 中的该主题声明如下:“首次为 Liberty 服务器启用安全性时默认配置 LTPA。”很明显,只要我为 Liberty 服务器启用了安全性,它就会生成 LTPA 密钥;并且禁用 Liberty 服务器中的安全性对我来说不是一个选项。所以我不相信我可以阻止 Liberty 服务器在我的特定环境中生成 LTPA 密钥。
关于防止 Liberty 服务器将 LTPA 令牌/cookie 发送到客户端浏览器,Liberty 服务器似乎存在一个名为 disableLtpaCookie 的属性。但是,根据 Liberty 文档,我只能在 2 种情况下使用 disableLtpaCookie 属性 - 当我使用 OpenID Connect Client https://www.ibm.com/support/knowledgecenter/en/SSEQTP_liberty/com.ibm.websphere.liberty.autogen.base.doc/ae/rwlp_config_openidConnectClient.html 或当我使用 SAML Web SSO 2.0 Authentication https://www.ibm.com/support/knowledgecenter/en/SSEQTP_liberty/com.ibm.websphere.liberty.autogen.base.doc/ae/rwlp_config_samlWebSso20.html 时。如果我没有实现这些身份验证机制中的任何一个,那么我将无法使用 disableLtpaCookie 属性……因此我无法阻止 Liberty 服务器将 LTPA 令牌/cookie 发送到客户端浏览器。
我错过了什么吗?有没有办法阻止 Liberty 服务器生成 LTPA 密钥或阻止 Liberty 服务器将 LTPA 令牌/cookie 发送到我尚未通过 Liberty 文档发现的客户端浏览器?
非常感谢任何和所有指导,并提前感谢您!
【问题讨论】: