170
Novell Access Manager 3.1 SP2 Identity Server Guide
n
ov
do
cx (e
n)
16
Ap
ril 20
10
For instructions, see your Active Directory documentation.
2
Log in to the Active Directory domain, rather than the machine.
3
(Conditional) If you are using Internet Explorer, configure the Web browser to trust the Identity
Server:
3a
Click
Tools
>
Internet Options
>
Security
>
Local intranet
>
Sites
>
Advanced
.
3b
In the
Add this website to the zone
text box, enter the Base URL for the Identity Server,
then click
Add
.
In the configuration example, this is
http://amser.provo.novell.com
.
3c
Click
Close > OK
.
3d
Click
Tools
>
Internet Options
>
Advanced
.
3e
In the Security section, select
Enable Integrated Windows Authentication
, then click
OK
.
3f
Restart the browser.
4
(Conditional) If you are using Firefox, configure the Web browser to trust the Identity Server:
4a
In the URL field, specify
about:config
.
4b
In the
Filter
field, specify
network.n
.
4c
Double click
network.negotiate-auth.trusted-uris
.
This preference lists the sites that are permitted to engage in SPNEGO Authentication
with the browser. Specify a comma-delimited list of trusted domains or URLs.
For this example configuration, you would add
http://amser.provo.novell.com
to
the list.
4d
If the deployed SPNEGO solution is using the advanced Kerberos feature of Credential
Delegation, double-click
network.negotiate-auth.delegation-uris
. This
preference lists the sites for which the browser can delegate user authorization to the
server. Specify a comma-delimited list of trusted domains or URLs.
For this example configuration, you would add
http://amser.provo.novell.com
to
the list.
4e
Click
OK
, then restart your Firefox browser.
5
In the URL field, enter the base URL of the Identity Server with port and application. For this
example configuration:
http://amser.provo.novell.com:8080/nidp
The Identity Server should authenticate the user without prompting the user for authentication
information. If a problem occurs, check for the following configuration errors:
Verify the default user store and contract. See
Step 13
.
View the Identity Server logging file and verify the configuration. See
“Verifying the
Kerberos Configuration” on page 169
.
If you make any modifications to the configuration, either in the Administration Console
or to the
bcsLogin
file, restart Tomcat on the Identity Server.
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...