Novell ACCESS MANAGER 3.1 SP2 - IDENTITY SERVER GUIDE 2010 Manual page 227

Identity server guide
Hide thumbs Also See for ACCESS MANAGER 3.1 SP2 - IDENTITY SERVER GUIDE 2010:
Table of Contents

Advertisement

2h Click Next > Finish > OK.
2i Close the browser.
2j To verify that the correct certificate was installed, open the browser, then enter the base
URL of the Identity Server.
The certificate error should not appear in the URL line.
Configuring Linux Clients for CardSpace
The following instructions are for Linux clients running SUSE Linux Enterprise Server (SLES) 10.
They explain how to use the Bandit DigitalMe card selector, including how to download it, install it,
and configure it so that it trusts the Identity Server.
1 Verify that you have updated Firefox to 2.x or later. DigitalMe does not work with Firefox
1.5.x.
2 In Firefox, access the Bandit Card site by entering the following URL:
http://cards.bandit-project.org
3 Click Download a selector, then select to download the selector for OpenSUSE.
4 Scroll to the bottom of the page, and install the Firefox add-on.
4a Click Download DigitalMe add-on for Firefox (All Platforms).
4b If you haven't enabled the Bandit site to install plug-ins, click Edit Options, then enable
the site and install the add-on.
5 Download the appropriate selector for your OS. For SLES 10 with 32-bit hardware, select
Download DigitalMe for SUSE Linux Enterprise 10 (i586) and save it as a file.
6 Close Firefox.
7 Open the download and install it.
8 Export the public key certificates of the Identity Server. You need both the CA and server
certificates.
The following instructions explain how to log in to the Administration Console from the client
machine with DigitalMe and export the certificates to the required directory.
8a From a browser on the DigitalMe machine, log into the Administration Console.
8b Click Security > Certificates.
8c Click the name of the Identity Server certificate, then click Export Public Certificate >
DER File.
8d Select to save the file to disk, then click OK.
8e Click Close, then click Trusted Roots.
8f Click the name of the trusted root (the default name is configCA), then select to Export
Public Certificate > DER File.
8g Select to save the file to disk, then click OK.
8h Copy the two certificate files to the following directory:
/usr/share/digitalme/certs
9 From the Application Browser, start the DigitalMe card selector.
10 At the prompt to create a default keying, enter a password, reenter the password, then click OK.
Configuring CardSpace 227

Advertisement

Table of Contents
loading

Table of Contents