Use this page to specify the related configuration need to specify the key for XML digital signature or XML encryption. To view this administrative console page on the cell level for the key information references, complete the following steps:
To view this administrative console page on the server level for the key information references, complete the following steps:
To view this administrative console page on the application level for the key information references, complete the following steps.
Note: This option is available on the application level for V6.0.x applications.
Before clicking Properties under Additional properties, enter a value in the Key information name field and select an option for the Key information type and Key locator reference options.
Specifies a name for the key information configuration.
Timeype of key information. The key information type specifies how to reference security tokens. This product supports the following types of key information. Each type of key information is described in Web Services Security: SOAP Message Security 1.0 (WS-Security 2004)
Type | Description |
---|---|
Key identifier | The security token is referenced using an opaque value that uniquely identifies the token. |
Key name | The security token is referenced using a name that matches an identity assertion within the token. |
Security token reference | With this type, the security token is directly referenced. |
Embedded token | With this type, the security token reference is embedded. |
X509 issuer name and issuer serial | With this type, the security token is referenced by an issuer and serial number of an X.509 certificate |
The X.509 issuer name and issuer serial is described in Web Services Security: X.509 Certificate Token Profile Version 1.0. The other types are described in Web Services Security: SOAP Message Security 1.0 (WS-Security 2004). If you select Key identifier for the key information type, you can specify values in the following fields on this panel:
Specifies the reference that is used to retrieve the key for digital signature and encryption. Before specifying a key locator reference, configure a key locator. You can specify a signing key configuration for the following bindings:
Binding name | Cell level, server level, or application level | Path |
---|---|---|
Default generator binding | Cell level |
|
Default consumer binding | Cell level |
|
Default generator binding | Server level |
|
Default consumer binding | Server level |
|
Request sender binding | Application level |
|
Response receiver binding | Application level |
|
Request receiver binding | Application level |
|
Response sender binding | Application level |
|
Request generator (sender) binding | Application level |
|
Response consumer (receiver) binding | Application level |
|
Request consumer (receiver) binding | Application level |
|
Response generator (sender) binding | Application level |
|
Specifies the name of the key that is used for generating digital signature and encryption.
This field is displayed for the default generator and is also displayed for the request generator and response generator for V6.0.x applications.
Binding name | Cell level, server level, or application level | Path |
---|---|---|
Default generator binding | Cell level |
|
Default generator binding | Server level |
|
Request generator (sender) binding | Application level |
|
Response generator (sender) binding | Application level |
|
Specifies the name of a token generator or token consumer that is used for processing a security token. The application server requires this field only when you specify Security token reference or Embedded token in the Key information type field. The Token reference field is also required when you specify a key identifier type for the consumer. Before specifying a token reference, configure a token generator or token consumer. You can specify a token configuration for the following bindings on the following levels:
Binding name | Cell level, server level, or application level | Path |
---|---|---|
Default generator binding | Cell level |
|
Default consumer binding | Cell level |
|
Default generator binding | Server level |
|
Default consumer binding | Server level |
|
Request generator (sender) binding | Application level |
|
Response consumer (receiver) binding | Application level |
|
Request consumer (receiver) binding | Application level |
|
Response generator (sender) binding | Application level |
|
Specifies the encoding method that indicates the encoding format for the key identifier. This field is valid when you specify Key identifier in the Key information type field. This product supports the following encoding methods:
This field is available for the default generator binding only.
This field is available for the generator binding only.
Specifies the namespace Uniform Resource Identifier (URI) of the value type for a security token that is referenced by the key identifier.
This field is valid when you specify Key identifier in the Key information type field. When you specify the X.509 certificate token, you do not need to specify this option. If you want to specify another token, specify the URI of QName for value type. This product provides the following predefined value type URIs for the Lightweight Third Party Authentication (LTPA) token:
This field is available for the generator binding only.
Local name of the value type for a security token that is referenced by the key identifier.
When this local name is used with the corresponding namespace URI, the information is called the value type qualified name or QName. This field is valid when you specify Key identifier in the Key information type field. When you specify the X.509 certificate token, IBM recommends that you use the predefined local names. When you specify the predefined local names, you do not need to specify the URI of the value type. This product provides the following predefined local names:
When you specify a custom value type for custom tokens, you can specify the local name and the URI of the quality name (QName) of the value type. For example, you might specify Custom for the local name and http://www.ibm.com/custom for the URI.
This field is also available for the generator binding only.