Novell ACCESS MANAGER 3.1 SP1 - IDENTITY SERVER Manual page 189

Identity server guide
Table of Contents

Advertisement

To create a new authentication contract:
1 Log in to the Administration Console.
2 Click Devices > Identity Servers > Edit > Local > Contracts.
3 Click New, and fill in the following fields:
Display name: Specify a name, for example WS-Fed Contract.
URI: Specify a URI, for example https://idp-50.amlab.net:8443/nidp/name/password/uri.
Satisfiable by External Provider: Enable this option. The ADFS server needs to satisfy this
contract.
4 Move Name/Password – Form to the Methods list.
5 Click Next, then fill in the following fields:
ID: Leave this field blank. You only need to supply a value when you want a reference that you
can use externally.
Text: Specify a description that is available to the user when the user mouses over the card.
Image: Select an image, such as Form Auth Username Password. This is the default image for
the Name/Password - Form contract.
Show Card: Enable this option so that the card can be presented to the user as a log in option.
6 Click Finish.
7 Continue with
"Setting the WS-Fed Contract to Be the Default Contract" on page
Setting the WS-Fed Contract to Be the Default Contract
There is no way to specify what contract to request from the ADFS service provider to the Identity
Server. You must either set the contract for WS-Fed to be the default, or have your users remember
to click that contract every time.
1 On the Local page of the Identity Server, click Defaults.
2 For the Authentication Contract option, select the WS-Fed Contract.
3 Click Apply.
4 Continue with
"Enabling the STS and WS Federation Protocols" on page
Enabling the STS and WS Federation Protocols
Access Manager ships with only SAML 1.1, Liberty, and SAML 2.0 enabled by default. In order to
use the WS Federation protocol you must enabled it on the Identity Server. Because the WS
Federation Protocol uses the STS (Secure Token Service) protocol, STS must also be enabled.
1 Click the General tab.
2 In the Enabled Protocols section, select the STS and WS Federation protocols.
3 Click OK.
4 Update the Identity Server.
5 Continue with
"Creating an Attribute Set for WS Federation" on page
189.
189.
190.
Configuring WS Federation 189

Advertisement

Table of Contents
loading

This manual is also suitable for:

Access manager 3.1 sp1

Table of Contents