Novell ACCESS MANAGER 3.1 SP1 - IDENTITY SERVER Manual page 157

Identity server guide
Table of Contents

Advertisement

The system displays the Create Trusted Identity Provider Wizard that lets you obtain the
metadata. Follow the on-screen instructions to complete the steps in the wizard.
3 Select either Metadata URL or Metadata Text, then fill in the field for the metadata on the page.
4 To edit the metadata manually, click Edit.
5 Fill in the following fields as necessary:
Supported Version: Specifies the version of SAML that you want to use.
Provider ID: (Required) The SAML 1.1 metadata unique identifier for the provider. For
example, https://<dns>:8443/nidp/saml/metadata. Replace <dns> with the DNS name of the
provider.
Source ID: The SAML Source ID for the trusted provider. The Source ID is a 20-byte value
that is used as part of the Browser/Artifact profile. It allows the receiving site to determine the
source of received SAML artifacts. If none is specified, the Source ID is auto-generated using a
SHA-1 hash of the site provider ID.
Metadata expiration: The date upon which the metadata is no longer valid.
SAML attribute query URL: The URL location where an attribute query is to be sent to the
partner. The attribute query requests a set of attributes associated with a specific object. A
successful response contains assertions that contain attribute statements about the subject. A
SAML 1.1 provider might use the base URL, followed by /saml/soap. For example, https://
<dns>:8443/nidp/saml/soap. Replace <dns> with the DNS name of the provider.
Artifact resolution URL: The URL location where artifact resolution queries are sent. A
SAML artifact is included in the URL query string. The target URL on the destination site the
user wants to access is also included on the query string. A SAML 1.1 provider might use the
base URL, followed by /saml/soap. For example, https://<dns>:8443/nidp/saml/soap. Replace
<dns> with the DNS name of the provider.
6 To specify signing certificate settings, fill in the following fields:
Attribute authority: Specifies the signing certificate of the partner SAML 1.1 attribute
authority. The attribute authority relies on the identity provider to provide it with authentication
information so that it can retrieve attributes for the appropriate entity or user. The attribute
authority must know that the entity requesting the attribute has been authenticated to the
system.
Configuring SAML and Liberty Trusted Providers 157

Advertisement

Table of Contents
loading

This manual is also suitable for:

Access manager 3.1 sp1

Table of Contents