2 Right click the account partner, then create a new Incoming Group Claim Mapping with the
following values:
Incoming group claim name: Specify ClaimApp.
Organization group claim: Specify Adatum ClaimApp Claim.
3 Right-click the account partner, and create another Incoming Group Claim Mapping with the
following values:
Incoming group claim name: Specify TokenApp.
Organization group claim: Specify Adatum TokenApp Claim.
4 Continue with
"Disable CRL Checking" on page
Disable CRL Checking
If you are using the Access Manager certificate authority as your trusted root for the signing
certificate (test-signing certificate), there is no CRL information in that certificate. However, the
ADFS has a hard requirement to do CRL checking on any certificate that they receive. For
instructions on how to disable this checking, see
go.microsoft.com/fwlink/?LinkId=68608).
Use the following tips as you follow these instructions.
Create a file from the script contained at that link called
Exit the Active Directory Federation Services console.
If you do not exit the console, the console overwrites the changes made by the script file and
CRL checking is not turned off.
Run the command with the following syntax:
Cscript TpCrlChk.vbs <location of ADFS>\TrustPolicy.xml "<service URI>"
None
Replace <location of ADFS> with the location of the ADFS
default location is
C:\ADFS\TrustPolicy.xml
Replace <service URI> with the URI you specified in
your Identity Server is idp-50.amlab.net, replace it with the following value: https://idp-
50.amlab.ne:8443/nidp/wsfed/.
Your command should look similar to the following:
Cscript TpCrlChk.vbs C:\ADFS\TrustPolicy.xml "https://idp-
50.amlab.net:8443/nidp/wsfed/" None
7.1.3 Logging In
1 On your client machine, enter the URL of the SharePoint server. For example:
https://adfsweb.treyresearch.net/default.aspx
2 Select the IDP from the drop down list of home realm and submit.
If you are not prompted for the realm, clear all cookies in the browser and try again.
3 Log in with a user at the Novell Identity Provider
195.
Turn CRL checking on or off (http://
TpCrlChk.vbs
TrustPolicy.xml
.
Step 3 on page
.
file. The
194. If the DNS name of
Configuring WS Federation 195
Need help?
Do you have a question about the ACCESS MANAGER 3.1 SP1 - IDENTITY SERVER and is the answer not in the manual?