The Wonder Which is
TAM/WebSEAL
IPS SME Series
©2011 MasterCard.
Proprietary and Confidential
Tivoli Access Manager for e-business
What is it?
• Web Access Management Solution
– Unified set of security services
– Policy based authorization services
– AAA – Authentication, Authorization, Accounting
– Implements decider-enforcer model (ISO 10181-3)
• Components
– PD (Policy Manager), Authorization Server (PDACLD),
PDJRTE, WebSEAL
– PD – Administration
– PDACLD – Runtime policy decisions
– WebSEAL – Web Front-end
MasterCard. 2011© April 23, 2012
Proprietary and Confidential Page 2
Unified Access Control
Application to Centralized
MasterCard. 2011© April 23, 2012
Proprietary and Confidential Page 3
Tivoli Access Manager for e-business
WebSEAL
• Web Secure Reverse Proxy
– Intercepts all web requests
– Shields URIs from direct access
MasterCard. 2011© April 23, 2012
Proprietary and Confidential Page 4
Tivoli Access Manager for e-business
Securing URIs
Junctions to back-end URIs
MasterCard. 2011© April 23, 2012
Proprietary and Confidential Page 5
Tivoli Access Manager for e-business
Policy
3 Types of Authorization Policy – ACLs, POPs, Rules
MasterCard. 2011© April 23, 2012
Proprietary and Confidential Page 6
Tivoli Access Manager for e-business
Policy Hierarchy
MasterCard. 2011© April 23, 2012
Proprietary and Confidential Page 7
Tivoli Access Manager for e-business
IPS WebSEALs
• CSRHW – CSRs with HW Authentication - FSSO
• CSRSW – CSRs with SW Authentication
• Anonymous – Gift cards
• WSSW – External Web Services
• Cardholder – Cardholder Access
• Util – Internal Only
MasterCard. 2011© April 23, 2012
Proprietary and Confidential Page 8
Tivoli Access Manager for e-business
Questions
MasterCard. 2011© April 23, 2012
Proprietary and Confidential Page 9