132
Novell Access Manager 3.1 SP2 Identity Server Guide
n
ov
do
cx (e
n)
16
Ap
ril 20
10
The Identity Server has not implemented all possible types. For types that do not appear on the
Defaults page, you can do one of the following:
You can define a contract for the class whose URI matches the requested class type. When the
authentication request is received, the Identity Server uses the URI to match the request with a
contract.
When you create such a contract, you are stating that the contract is security equivalent to the
class that is being requested. For configuration information, see
Section 3.5.2, “Creating a
Contract for a Specific Authentication Type,” on page 132
.
You can use the Trust Levels class to assign an authentication level for the requested class. This
level is used to rank the requested type. Using the authentication level and the comparison
context, the Identity Server can determine whether any contracts meet the requirements of the
request. If one or more contracts match the request, the user is presented with the appropriate
authentication prompts.
For configuration information, see
Section 7.2.4, “Configuring the Trust Levels Class,” on
page 189
.
3.5.2 Creating a Contract for a Specific Authentication Type
The following steps explain how to create a contract that matches what a trusted service provider is
asking for in its authentication request.
1
In the Administration Console, click
Devices > Identity Servers > Edit > Local > Contracts
.
2
To create a new contract, click
New
.
3
Fill in the following fields:
Display name:
Specifies the name of the authentication contract.
URI:
Specifies a value that uniquely identifies the contract from all other contracts. This value
must match what the service provider is sending in its authentication request for the type.
Authentication Level:
(Optional) Specify a security level or rank for the contract. This value
is not used when authentication request sets the comparison type to exact. It is only used when
a contract is selected based on a comparison of authentication levels.
If the service provider sets the comparison type to minimum, the authentication level can be the
same or higher. If the comparison type is set to better, the authentication level must be higher.
Methods:
Select the method that matches the class or type you specified in the URI.
The other fields for the contract are not requirements of the authentication request and can be
configured to meet the requirements of the Identity Server. For information about these fields,
see
Section 3.4, “Configuring Authentication Contracts,” on page 124
.
4
Click
Next
.
5
Configure an authentication card for the contract.
For information about these fields, see
Section 3.4, “Configuring Authentication Contracts,”
on page 124
.
6
Click
Finish
, then
OK.
7
Update the Identity Server.
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...