Configuring SAML and Liberty Trusted Providers
185
n
ov
do
cx (e
n)
16
Ap
ril 20
10
Figure 7-2
Embedded Service Provider
7.1.3 Configuration Overview
The following high-level tasks describe the process required to set up the trust model between an
identity provider and a service provider. Although these tasks assume that both providers are
Identity Servers provided with Access Manager, similar tasks must be performed when one of the
providers is a third-party application.
1. Administrators at each company install and configure the Identity Server.
See
Section 1.1.1, “Creating a Cluster Configuration,” on page 16
. (You should already be
familiar with the
Novell Access Manager 3.1 SP2 Installation Guide
.)
2. Administrators at each company must import the trusted root certificate of the other Identity
Server into the NIDP trust store.
Click
Devices
>
Identity Servers
>
Servers
>
Edit
>
Security
>
NIDP Trust Store
, then auto
import the certificate. Use the SSL port (8443) even if you haven’t set up the base URL of the
Identity Server to use HTTPS.
3. Administrators must exchange Identity Server metadata with the trusted partner.
Metadata is generated by the Identity Server and can be obtained via a URL or an XML
document, then entered in the system when you create the reference. This step is not applicable
if you are referencing an ESP. When you reference an ESP, the system lists the installed ESPs
for you to choose, and no metadata entry is required.
4. Create the reference to the trusted identity provider and the service provider.
This procedure associates the metadata with the new provider. See
Section 7.3.1, “Creating a
Trusted Provider for Liberty or SAML 2.0,” on page 190
.
5. Configure user authentication.
This procedure defines how your Identity Server interacts with the trusted provider during user
authentication. Access Manager comes with default basic authentication settings already
enabled. See
Chapter 11, “Configuring User Identification Methods for Federation,” on
page 277
.
Additional important steps for enabling authentication between trusted providers include:
Setting up the necessary authentication contracts. See
Section 3.4, “Configuring
Authentication Contracts,” on page 124
.
Trusted ESP
Access Gateway
Protected
Application
Payroll Identity Server (IDP)
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...