Novell ACCESS MANAGER 3.1 SP2 - IDENTITY SERVER GUIDE 2010 Manual page 218

Identity server guide
Hide thumbs Also See for ACCESS MANAGER 3.1 SP2 - IDENTITY SERVER GUIDE 2010:
Table of Contents

Advertisement

<identity consumer URL>?PID=<entityID>&TARGET=<final_destination_URL>
The <identity_consumer_URL> is the location of where the authentication request can be
processed. For an Access Manager Identity Server, the URL is the Base URL of the server that is
providing authentication, followed by the path to the protocol application being used for federation.
For example:
SAML 1.1:
SAML 2.0:
Liberty:
https://idp.sitea.novell.com:8443/nidp/idff/idpsend
If a third-party server is providing the authentication, search its documentation for the format of this
URL.
The <entityID> is the URL to the location of the metadata of the service provider. The scheme (http
or https) in the <entityID> must match what is configured for the <identity_consumer_URL>. For
SAML 1.1 and SAML 2.0, search the metadata for its entityID value. For Liberty, search the
metadata for its providerID value. Novell Identity Servers acting as service providers have the
following types of values:
SAML 1.1:
SAML 2.0:
Liberty:
https://idp.siteb.novell.com:8443/nidp/idff/metadata
If you are setting up federations with a third-party service provider, search its documentation for the
URL or location of its metadata.
The <final_destination_URL> is the URL to which the browser is redirected following a successful
authentication at the identity provider. If this target URL contains parameters (for example,
TARGET=https://login.provo.novell.com:8443/nidp/app?function_id=22166&
amp;Resp_Id=55321 &amp;Resp_App_Id=810&amp;security_id=0
to prevent the URL from being truncated.
Examples with all three parts:
SAML 1.1:
idp.siteb.novell.com:8443/nidp/saml/metadata&TARGET=https://
eng.provo.novell.com/saml1/myapp
SAML 2.0:
/idp.siteb.novell.com:8443/nidp/saml2/metadata&TARGET=https://
eng.provo.novell.com/saml2/myapp
Liberty:
idp.siteb.novell.com:8443/nidp/idff/metadata&TARGET=https://
eng.provo.novell.com/liberty/myapp
If you are configuring an Intersite Transfer Service URL for an Identity Server that is the identity
provider and the service provider is either another Identity Server or a third-party server, you can
simplify the Intersite Transfer Service URL to the following format:
<identity consumer URL>?id=<user_definedID>
218 Novell Access Manager 3.1 SP2 Identity Server Guide
https://idp.sitea.novell.com:8443/nidp/saml/idpsend
https://idp.sitea.novell.com:8443/nidp/saml2/idpsend
https://idp.siteb.novell.com:8443/nidp/saml/metadata
https://idp.siteb.novell.com:8443/nidp/saml2/metadata
https://idp.sitea.novell.com:8443/nidp/saml/idpsend?PID=https://
https://idp.sitea.novell.com:8443/nidp/saml2/idpsend?PID=https:/
https://idp.sitea.novell.com:8443/nidp/idff/idpsend?PID=https://
), it must be URL encoded

Advertisement

Table of Contents
loading

Table of Contents