Novell ACCESS MANAGER 3.1 SP1 - IDENTITY SERVER Manual page 70

Identity server guide
Table of Contents

Advertisement

2b To replace a certificate, click Replace, browse to locate the certificate, then click OK.
3 To manage trust stores associated with the Identity Server:
3a Click either of the following links on the Security page:
NIDP Trust Store: This Identity Server trust store contains the trusted root certificates of
all the providers that it trusts. Liberty and SAML 2.0 protocol messages that are
exchanged between identity and service providers often need to be digitally signed. A
provider uses the signing certificate included with the metadata of a trusted provider to
validate signed messages from the trusted provider. The trusted root of the CA that created
the signing certificate for the service provider needs to be in this trust store.
To use SSL for protocol messages to be exchanged between providers, each provider must
trust the SSL certificate authority (CA) of the other provider. You must import the root
certificate chain for the other provider. Failure to do so causes numerous system errors.
OCSP Trust Store: The Identity Server uses this trust store for OCSP certificates. Online
Certificate Status Protocol is a method used for checking the revocation status of a
certificate. To use this feature, you must set up an OCSP server. The Identity Server sends
an OCSP request to the OCSP server to determine if a certain certificate has been revoked.
The OCSP server replies with the revocation status. If this revocation checking protocol is
used, the Identity Server does not cache or store the information in the reply, but sends a
request every time it needs to check the revocation status of a certificate. The OCSP reply
is signed by the OCSP server. To verify that it was signed by the correct OCSP server, the
OCSP server certificate needs to be added to this trust store. The OCSP server certificate
itself is added to the trust store, not the CA certificate.
For example, if you click the NIDP Trust Store, the following page appears:
70
Novell Access Manager 3.1 SP1 Identity Server Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Access manager 3.1 sp1

Table of Contents