Configuring User Identification Methods For Federation; Defining User Identification For Liberty And Saml 2.0; Selecting A User Identification Method For Liberty Or Saml 2.0 - Novell ACCESS MANAGER 3.1 SP2 - IDENTITY SERVER GUIDE 2010 Manual

Identity server guide
Hide thumbs Also See for ACCESS MANAGER 3.1 SP2 - IDENTITY SERVER GUIDE 2010:
Table of Contents

Advertisement

Configuring User Identification
1 1
Methods for Federation
Configuring authentication involves determining how the service provider interacts with the identity
provider during user authentication and federation. Three methods exist for you to identify users
from a trusted identity provider:
You can identify users by matching their authentication credentials
You can match selected attributes and then prompt for a password to verify the match, or you
can use just the attributes for the match.
You can assume that the user does not have an account and create new accounts with user
provisioning. You can also allow for provisioning when the matching methods fail. If there are
problems during provisioning, you see error messages with more information.
The following sections describe how to configure these methods:
Section 11.1, "Defining User Identification for Liberty and SAML 2.0," on page 277
Section 11.2, "Defining User Identification for SAML 1.1," on page 280
Section 11.3, "Defining the User Provisioning Method," on page 282
Section 11.4, "User Provisioning Error Messages," on page 286
11.1 Defining User Identification for Liberty and
SAML 2.0
Section 11.1.1, "Selecting a User Identification Method for Liberty or SAML 2.0," on page 277
Section 11.1.2, "Configuring the Attribute Matching Method for Liberty or SAML 2.0," on
page 279
11.1.1 Selecting a User Identification Method for Liberty or
SAML 2.0
User identification determines how an account at the identity provider is matched with an account at
the service provider. If federation is enabled between the two, the user can set up a permanent
relationship between the two accounts. If federation is not enabled (see
Authentication Request for an Identity Provider," on page
identification method.
1 In the Administration Console, click Devices > Identity Servers > Edit > Liberty [or SAML
2.0] > [Identity Provider] > User Identification.
Section 7.8, "Configuring an
207), you cannot set up a user

Configuring User Identification Methods for Federation

11
277

Advertisement

Table of Contents
loading

Table of Contents