Novell ACCESS MANAGER 3.1 SP2 - IDENTITY SERVER GUIDE 2010 Manual page 255

Identity server guide
Hide thumbs Also See for ACCESS MANAGER 3.1 SP2 - IDENTITY SERVER GUIDE 2010:
Table of Contents

Advertisement

2 Move the WS Federation attribute set to the Attribute set list.
3 Select the WS Federation attribute set and use the up-arrow to make it first in the Attribute set
list.
4 Click OK, then update the Identity Server.
Creating a WS Federation Service Provider
In order to establish a trusted relationship with the ADFS server, you need to set up the Trey
Research site as a service provider. The trusted relationship allows the service provider to trust the
Identity Server for user authentication credentials.
Trey Research is the default name for the ADFS resource server. If you have used another name,
substitute it when following these instructions. To create a service provider, you need to know the
following about the ADFS resource server.
ADFS Resource Server Information
Table 10-1
What You Need to Know
Default Value and Description
Provider ID
Default Value:
This is the value that the ADFS server provides to the Identity Server in the
realm parameter of the query string. This value is specified in the Properties of
the Trust Policy page on the ADFS server. The parameter label is Federation
Service URI.
Sign-on URL
Default Value:
This is the value that the identity provider redirects the user to after login.
Although it is listed as optional, and is optional between two Novell Identity
Servers, the ADFS server doesn't send this value to the identity provider. It is
required when setting up a trusted relationship between an ADFS server and a
Novell Identity Server.
This URL is listed in the Properties of the Trust Policy page on the ADFS
server. The parameter label is Federation Services endpoint URL.
Logout URL
Default Value:
This parameter is optional. If it is specified, the user is logged out of the ADFS
server and the Identity Server.
Signing Certificate
This is the certificate that the ADFS server uses for signing.
You need to export it from the ADFS server. It can be retrieved from the
properties of the Trust Policy on the ADFS Server on the Verification
Certificates tab.
This certificate is a self-signed certificate that you generated when following
the Active Directory step-by-step guide.
To create a service provider configuration:
1 On the Identity Servers page, click Edit > WS Federation.
2 Click New > Service Provider, then fill in the following fields:
Name: Specify a name that identifies the service provider, such as
urn:federation:treyresearch
https://adfsresource.treyresearch.net/adfs/ls/
https://adfsresource.treyresearch.net/adfs/ls/
.
TreyResearch
Configuring WS Federation 255

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the ACCESS MANAGER 3.1 SP2 - IDENTITY SERVER GUIDE 2010 and is the answer not in the manual?

Questions and answers

Table of Contents