Novell ACCESS MANAGER 3.1 SP1 - IDENTITY SERVER Manual page 199

Identity server guide
Table of Contents

Advertisement

2 In the Enabled Protocols section, then enable the STS and WS Federation protocols.
3 Click OK.
4 Update the Identity Server.
5 Continue with
"Create a WS Federation Identity Provider" on page
Create a WS Federation Identity Provider
In order to have a trust relationship, you need to set up the Adatum site (adfsaccount.adatum.com) as
an identity provider for the Identity Server.
Adatum is the default name for the identity provider. If you have used another name, substitute it
when following these instructions. To create an identity provider, you need to know the following
about the Adatum site.
Adatum Values
Table 7-2
What You Need to Know Default Value and Description
Provider ID
The default value is urn:federation:adatum.
The ADFS server provides this value to the service provider in the realm
parameter in the assertion. You set this value in the Properties of the Trust
Policy on the ADFS server. The label is Federation Service URI.
Sign-on URL
The default value is https://adfsaccount.adatum.com/adfs/ls/.
The service provider uses this value to redirect the user for login. This URL is
listed in the Properties of the Trust Policy on the ADFS server. The label is
Federation Services endpoint URL.
Logout URL
The default value is https://adfsresource.treyresearch.net/adfs/ls/.
The ADFS server makes no distinction between the login and logout URL.
Access Manager has separate URLs for login and logout, but from a Novell
Identity Server to an ADFS server, they are the same.
Signing Certificate
This is the certificate that the ADFS server uses for signing.
You need to export it from the ADFS server. It can be retrieved from the
properties of the Trust Policy on the ADFS Server on the Verification
Certificates tab.
This certificate is a self-signed certificate that you generated when following the
step-by-step guide.
To create an identity provider:
1 In the Administration Console, click Devices > Identity Servers > Edit > WS Federation.
2 On the WS Federation page, click New, select Identity Provider, then fill in the following
fields:
Name: Specify a name that identifies the identity provider, such as Adatum.
Provider ID: Specify the federation service URI of the identity provider, for example
urn:federation:adatum.
199.
Configuring WS Federation 199

Advertisement

Table of Contents
loading

This manual is also suitable for:

Access manager 3.1 sp1

Table of Contents