
76 Enterprise Business Portals with IBM Tivoli Access Manager
Now that we have addressed the communication among the components, our
new architecture is shown in Figure 3-5.
Figure 3-5 Detailed WebSEAL security architecture with internal WebSEAL
Important: If you place a production Web server under WebSEAL access
control, it is recommended that you do not allow access to it via
non-WebSEAL channels without careful consideration. Prior experience has
shown that this can lead to confusion, manageability issues, and most
important, security breaches.
Generally, co-locating internal WebSEALs with Web servers is acceptable to
many organizations; howe ...