Novell ACCESS MANAGER 3.1 SP1 - IDENTITY SERVER Manual page 163

Identity server guide
Table of Contents

Advertisement

Transient Identifier Format: Specifies that a transient identifier, which expires between
sessions, can be sent.
If the request from the service provider requests a format that is not enabled, the user cannot
authenticate.
4 Use the Default button to specify whether a persistent or transient identifier is sent when the
request from the service provider does not specify a format.
5 To specify that this Identity Server must authenticate the user, disable the Use proxied requests
option. When the option is disabled and the Identity Server cannot authenticate the user, the
user is denied access.
When this option is enabled, the Identity Server checks to see if other identity providers can
satisfy the request. If one or more can, the user is allowed to select which identity provider
performs the authentication. If a proxied identity provider performs the authentication, it sends
the response to the Identity Server. The Identity Server then sends the response to the service
provider.
6 Enable the Provide Discovery Services option if you want to allow the service provider to query
the Identity Server for a list of its Web Services. For example, when the option is enabled, the
service provider can determine whether the Web Services Framework is enabled and which
Web Service Provider profiles are enabled.
7 Click OK twice, then update the Identity Server.
Configuring the SAML 1.1 Authentication Response
If the service provider does not request a specific format for the name identifier, you can specify the
format you want the Identity Server to send. You can also restrict the use of the assertion.
When an identity provider sends an assertion, the assertion can be restricted to an intended audience.
The intended audience is defined to be any abstract URI in SAML 1.1. The URL reference can also
identify a document that describes the terms and conditions of audience membership.
1 In the Administration Console, click Devices > Identity Servers > Edit > SAML 1.1 > [Service
Provider] > Authentication Response.
2 To specify a name identifier format, select one of the following:
E-mail: Specifies that an e-mail attribute can be used as the identifier.
Configuring SAML and Liberty Trusted Providers 163

Advertisement

Table of Contents
loading

This manual is also suitable for:

Access manager 3.1 sp1

Table of Contents