BlackFriday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IBM Exam C9510-401 Topic 8 Question 102 Discussion

Actual exam question for IBM's C9510-401 exam
Question #: 102
Topic #: 8
[All C9510-401 Questions]

A web application has a configured session timeout of eight hours and a default LTPA token timeout of two hours. After every two hours, the users have to log in again from their HTTP browser. The system administrator is required to make configuration changed so users only have to log in once, while keeping the above mentioned timeouts the same. The authentication mechanism available is Kerberos.

How should the administrator do this?

Show Suggested Answer Hide Answer
Suggested Answer: B

In WebSphere Application Server Version 6.1, a trust association interceptor (TAI) that uses the Simple and Protected GSS-API Negotiation Mechanism (SPNEGO) to securely negotiate and authenticate HTTP requests for secured resources was introduced. This function was deprecated In WebSphere Application Server 7.0. SPNEGO web authentication has taken its place to provide dynamic reload of the SPNEGO filters and to enable fallback to the application login method.

References: https://www.ibm.com/support/knowledgecenter/en/SSAW57_8.5.5/com.ibm.websphere.nd.doc/ae/csec_ssovo.html


Contribute your Thoughts:

Ayesha
12 days ago
C) Enable Session Management Security Integration. This sounds like it could be the solution, but I'm not entirely sure how it works with the given timeouts.
upvoted 0 times
...
Pamella
15 days ago
D) Ensure Web Inbound security attribute propagation is enabled. This should allow the session to be maintained across the eight-hour timeout.
upvoted 0 times
...
Felicia
20 days ago
I agree with Stephane. Configuring SPNEGO would allow users to log in only once while maintaining the session and token timeouts.
upvoted 0 times
...
Rolland
21 days ago
B) Configure the SPNEGO Web or SPNEGO TAI. This seems like the right option to me, as it allows for single sign-on using Kerberos.
upvoted 0 times
Hyman
9 days ago
A) Configure the SIP digest authentication.
upvoted 0 times
...
Alysa
10 days ago
B) Configure the SPNEGO Web or SPNEGO TAI. This seems like the right option to me, as it allows for single sign-on using Kerberos.
upvoted 0 times
...
...
Stephane
27 days ago
I think the administrator should configure the SPNEGO Web or SPNEGO TAI.
upvoted 0 times
...

Save Cancel