IBM(R) Tivoli(R) Access Manager WebSEAL OAuth External Authorization Service, 
Release 6.1.1.4-IF-AM-OAUTH-EAS (111107a)
===============================================================================

(C) Copyright International Business Machines Corporation 2011. All rights 
reserved. 
U.S. Government Users Restricted Rights -- Use, duplication or 
disclosure restricted by GSA ADP Schedule Contract with IBM Corp.

DATE:  Friday, 02 December 2011
			
    CONTENTS

	1.0 ABOUT THIS RELEASE
		1.1 Release Contents
		1.2 Architectures

	2.0 NEW FEATURES
	
	3.0 APARS AND DEFECTS FIXED

	4.0 INSTALLING THIS RELEASE

	5.0 CONFIGURING THIS RELEASE


1.0 ABOUT THIS RELEASE
----------------------

1.1 Release Contents

This release package contains:

- This README file
- Tivoli Access Manager WebSEAL OAuth EAS libraries for supported platforms

1.2 Architectures

Below are a the list of supported architectures

	rios_aix_5			AIX (Power)
	hp9000_ux_11		HP-UX (PA-RISC)
	ia64_hpux_11		HP-UX (Itanium)
	sparc_solaris_2		Solaris (SPARC)
	x86_solaris_2		Solaris (x86)
	x86_linux_2			Linux (x86)
	ppc_linux_2			Linux (Power)
	s390_linux_2_x86	Linux (S/390)
	x86_nt_4			Windows (x86)


This patch package applies to the following operating systems and patch levels:

AIX
---

Note: Tivoli Access Manager components for AIX are supported on
32-bit and 64-bit kernels in 32-bit compatibility mode.

5.2 - AIX Technology Level (TL) 5200-08 or above
- AIX Service Pack (SP) 5200-08-2 or above

5.3 - AIX Technology Level (TL) 5300-04 or above
- AIX Service Pack (SP) 5200-08-2 or above

6.1 - none
6.1 WPAR - none

HP-UX
-----

The following patches are required for HP-UX:

11iv2 (B.11.23)
PA-RISC
- PHSS_33449
- PHSS_33450
- PHSS_33405

Integrity
- PHSS_34859
- PHSS_35978

11iv3 (B.11.31)
PA-RISC
- PHSS_33449
- PHSS_33450
- PHSS_33405

Integrity
- PHSS_34859
- PHSS_35978

Solaris
-------

Note: Tivoli Access Manager components for Solaris on x86-64 architecture are
supported on 64-bit AMD64 systems.

Solaris 9

SunSparc - Recommended Patch Cluster of Dec 2007

Solaris 10

SunSparc
Global/Local Zones - Recommended Patch Cluster of Dec 2007

x86-64
Global/Local Zones - none

x86 Linux
---------

Note: Tivoli Access Manager components for Linux on x86-64 architecture are
supported on 64-bit AMD64/EM64T systems.

Red Hat Enterprise

Linux Server 4.0
x86 and x86-64 - Update 5

Linux Server 5.0
x86 and x86-64 - none

SUSE Linux

Enterprise Server 9
x86 and x86-64 - Service Pack 2

Enterprise Server 10
x86 and x86-64 - none

zLinux
------

Note: Tivoli Access Manager components for Linux on zSeries are supported on
64-bit kernels in 31-bit compatibility mode.

Red Hat Enterprise

Linux Server 4.0
(zSeries) - Update 5 or above
compat-libstdc++-295-2.95.3-81.s390.rpm or higher version
compat-libstdc++-295-2.95.3-81.s390x.rpm or higher version
compat-libstdc++-33-3.2.3-47.3.s390.rpm or higher version
compat-libstdc++-33-3.2.3-47.3.s390x.rpm or higher version
Linux Server 5.0
(zSeries) - compat-libstdc++-295-2.95.3-81.s390.rpm or higher version
compat-libstdc++-295-2.95.3-81.s390x.rpm or higher version
compat-libstdc++-33-3.2.3-47.3.s390.rpm or higher version
compat-libstdc++-33-3.2.3-47.3.s390x.rpm or higher version

SUSE Linux
Enterprise Server 9
(zSeries) - Service Pack 3 or above
compat-2004.7.1-1.2.s390x.rpm or higher version
compat-32bit-9-200407011411.s390x.rpm or higher version

Enterprise Server 10
(zSeries) - compat-2006.1.25-11.2.s390x.rpm or higher version
compat-32bit-2006.1.25-11.2.s390x.rpm or higher version

Microsoft Windows
-----------------

Note: Tivoli Access Manager components for Windows Servers are supported
on AMD64/EM64T systems with 64-bit kernels in 32-bit compatibility mode.

Windows Server 2003
Standard & Enterprise Edition
x86 - Service Pack 2
x86-64 - Service Pack 2

Windows Server 2008
Standard & Enterprise Edition
x86 - none
x86-64 - none

Virtualized Environments
------------------------

z/VM 6.1 on System z10 Processor TAM611 Fix Pack 01
Resource/Systems Manager

AIX 6.1 on POWER7 PowerVM TAM611 Fix Pack 01
for both POWER7 mode and
POWER6 compatibility mode
(Requires upgrade to ITDS 6.1
Fixpack 5 for POWER7 mode)

Red Hat Enterprise Linux Server TAM611 Fix Pack 01
5.0 Update 4 x86 on
Red Hat Enterprise Linux Server
5.0 Update 4 with
Kernel-Based Virtual Machine
(KVM) Hypervisor

Windows Server 2003 Service Pack 2 TAM611 Fix Pack 01
Standard & Enterprise Edition x86,
Windows Server 2008
Standard & Enterprise Edition x86,
Red Hat Enterprise Linux Server
4.0 Update 5 x86,
Red Hat Enterprise Linux Server
5.0 x86
on VMWare ESX and ESXi 4.0

2.0 NEW FEATURES
---------------------

Marketing Requests addressed in this release.

	MR#:  N/A (Internal)
	Description:  WebSEAL OAuth policy enforcement point support.
	Note: This EAS library provides OAuth policy enforcement point 
	functionality via an EAS library which can be used in conjunction
	with Tivoli Federated Identity Manager's OAuth service provider 
	functionality introduced in version 6.2.2 and Tivoli Access Manager 
	WebSEAL 6.1.1 Fix Pack 4.


3.0 APARS AND DEFECTS FIXED
---------------------------

Because releases are cumulative, this release corrects all the problems
outlined in the following sections.

	NONE

4.0 INSTALLING THIS RELEASE
---------------------------

	If the Tivoli Access Manager product is distributed over multiple
	machines this patch must be applied to all WebSEAL systems within a 
	secure domain.

	This README assumes that $PATCH is the path to
	your temporary directory.

	1. Log in to the system as a privileged user (root or Administrator)

	2. Extract the archive into a temporary directory. For the
	purpose of this README, assume that the symbol $PATCH
	points to this temporary directory.

	4. Copy the library into the pdwebrte/lib directory for your specific
	UNIX or Linux platform:

	UNIX or Linux:
		cp $PATCH/<platform>/ /opt/pdwebrte/lib/

	Windows:
		copy $PATCH\x86_nt_4\ C:\Program Files\Tivoli\PDWebRTE\lib\

	5. Configure the WebSEAL OAuth EAS

	For more information see the section titled 'Configuring the WebSEAL 
	OAuth EAS' in the Tivoli Federated Identity Manager 6.2.2
	Configuration Guide.

	6. Restart the Tivoli Access Manager WebSEAL processes:

	/opt/pdweb/bin/pdweb_start restart


5.0 CONFIGURING THIS RELEASE
---------------------------------

	For more detailed information about configuring the WebSEAL OAuth EAS, 
	see the section titled 'Configuring the WebSEAL OAuth EAS' in the 
	Tivoli Federated Identity Manager 6.2.2 Configuration Guide.
	
	Note: This release includes an oauth_eas.conf.template file which can be
	used as a template when configuring the OAuth parameters as part of
	step '1. (b)' in the 'Procedure' section of the 'Configuring the WebSEAL 
	OAuth EAS' in the configuration guide. 


IBM(R) Tivoli(R) Access Manager WebSEAL OAuth External Authorization Service, Release 6.1.1.4-IF-AM-OAUTH-EAS

