Novell ACCESS MANAGER 3.1 SP2 - IDENTITY SERVER GUIDE 2010 Manual page 193

Identity server guide
Hide thumbs Also See for ACCESS MANAGER 3.1 SP2 - IDENTITY SERVER GUIDE 2010:
Table of Contents

Advertisement

Shared the metadata URL of your Identity Server with the service provider or an XML file with
the metadata.
Enabled the protocol. Click Devices > Identity Servers > Edit, and on the Configuration page,
verify that the required protocol in the Enabled Protocols section has been enabled.
To create a service provider:
1 In the Administration Console, click Devices > Identity Servers > Edit > SAML 1.1.
2 Click New, then click Service Provider.
3 In the Name option, specify a name by which you want to refer to the provider.
4 Select one of the following sources for the metadata:
Metadata URL: Specify the metadata URL for a trusted provider. The system retrieves
protocol metadata using the specified URL. Examples of metadata URLs for an Identity Server
acting as a service provider with an IP address of 10.1.1.1:
http://10.1.1.1:8080/nidp/saml/metadata
https://10.1.1.1:8443/nidp/saml/metadata
The default values nidp and 8080 are established during product installation; nidp is the Tomcat
application name. If you have set up SSL, you can use https and port 8443.
If your Identity Server and Administration Console are on different machines, use HTTP to
import the metadata. If you are required to use HTTPS with this configuration, you must import
the trusted root certificate of the provider into the trust store of the Administration Console.
You need to use the Java
security directory of the Administration Console.
Linux:
/opt/novell/java/jre/lib/security
Windows Server 2003:
Windows Server 2008:
If you do not want to use HTTP and you do not want to import a certificate into the
Administration Console, you can use the Metadata Text option. In a browser, enter the HTTP
URL of the metadata. View the text from the source page, save the source metadata, then paste
it into the Metadata Text option.
Metadata Text: An editable field in which you can paste copied metadata text from an XML
document, assuming you obtained the metadata via e-mail or disk and are not using a URL. If
you copy metadata text from a Web browser, you must copy the text from the page source.
Manual Entry: Allows you to enter metadata values manually. When you select this option,
the system displays the Enter Metadata Values page. See
Provider's Metadata" on page
5 Click Next.
6 Review the metadata certificates, then click Finish.
7 Click OK, then update the Identity Server.
The wizard allows you to configure the required options and relies upon the default settings for
the other options. For information about how to configure the default settings and how to
configure the other available options, see
page
195.
to import the certificate into the
keytool
\Program Files\Novell\jre\lib\security
\Program Files (x86)\Novell\jre\lib\security
205.
Section 7.4, "Modifying a Trusted Provider," on
cacerts
"Editing a SAML 1.1 Service
Configuring SAML and Liberty Trusted Providers 193
file in the

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the ACCESS MANAGER 3.1 SP2 - IDENTITY SERVER GUIDE 2010 and is the answer not in the manual?

Table of Contents