Novell ACCESS MANAGER 3.1 SP1 - IDENTITY SERVER Manual page 164

Identity server guide
Table of Contents

Advertisement

X509: Specifies that an X.509 certificate can be used as the identifier.
Unspecified: Specifies that an unspecified format can be used and any value can be used.
The service provider and the identity provider need to agree on what value is placed in this
identifier.
3 To specify the format of the name identifier, select an attribute.
The available attributes depend upon the attributes that you have selected to send with
authentication (see the Attributes page for the service provider).
4 To configure an audience, click New.
5 Specify the SAML Audience URL value.
The Provider ID, which can be used for the audience, is displayed on the Edit page for the
metadata.
6 Click OK twice, then update the Identity Server.
Configuring the SAML 2.0 Authentication Response
After you create a trusted service provider, you can configure how your Identity Server responds to
authentication requests from the service provider.
1 In the Administration Console, click Devices > Identity Servers > Edit > SAML 2.0 > [Service
Provider] > Authentication Response.
2 Select the binding method.
If the request from the service provider does not specify a response binding, you need to
specify a binding method to use in the response. Select Artifact to provide an increased level of
security by using a back-channel means of communication between the two servers. Select Post
to use HTTP redirection for the communication channel between the two servers. If you select
Post, you might want to require the signing of the authentication requests. See
"Configuring the General Identity Provider Options," on page
3 Specify the identity formats that the Identity Server can send in its response. Select the box to
choose one or more of the following:
Persistent: Specifies that a persistent identifier, which is written to the directory and
remains intact between sessions, can be sent.
Transient: Specifies that a transient identifier, which expires between sessions, can be
sent.
164 Novell Access Manager 3.1 SP1 Identity Server Guide
Section 5.2.1,
144.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Access manager 3.1 sp1

Table of Contents