Configuring SAML and Liberty Trusted Providers
187
n
ov
do
cx (e
n)
16
Ap
ril 20
10
user. The service provider determines whether any of these identity providers can
authenticate a user without credentials. The service domain must resolve to the same IP
address as the base URL domain.
For example, if an agreed-upon common domain is
xyz.com
, the service provider can
specify a service domain of
sp.xyz.com
, and the identity provider can specify a service
domain of
idp.xyz.com
. For the identity provider,
xyz.com
is the common value entered,
and
idp
is the local value.
Port:
The port to use for identity provider introductions. Port 8445 for HTTPS is the
default and must be opened on your firewall. If you specify a different port, you must edit
the Tomcat
server.xml
file.
SSL Certificate:
Displays the Keystore page that you use to locate and replace the test-
provider SSL certificate for this configuration.
The Identity Server comes with a test-provider certificate that you must replace for your
production environment. This certificate is used for identity provider introductions. You can
replace the test certificate now or after you have configured the Identity Server. If you create
the certificate and replace the test-connector now, you can save some time by restarting Tomcat
only once. Tomcat must be restarted whenever you assign an Identity Server to a configuration
and whenever you update a certificate key store. See
Section 1.3.3, “Managing the Keys,
Certificates, and Trust Stores,” on page 29
.
3
Click
OK
, then update the Identity Server.
7.2.2 Configuring the General Identity Consumer Options
The following options affect all identity consumers (service providers) that the Identity Server has
been configured to trust.
1
In the Administration Console, click
Devices > Identity Servers > Edit > Identity Consumer
.
2
Specify whether the Identity Server can run as an identity consumer.
When the Identity Server is configured to run as an identity consumer, the Identity Server can
receive (consume) authentication assertions from other identity providers.
Enable:
Enables this site to function as service provider. This setting is enabled by default.
If this option is disabled, the Identity Server cannot trust or consume authentication assertions
from other identity providers. You can create and enable identity providers for the various
protocols, but they are not loaded or used until this option is enabled.
Require Signed Assertions:
Specifies that all SAML assertions received by the service
provider are signed by the issuing SAML authority. The signing authority uses a key pair to
sign SAML data sent to this trusted provider.
Sign Authentication Requests:
Specifies that the service provider signs authentication
requests sent to an identity provider when using the Liberty 1.2 and SAML 2.0 protocols.
Use Introductions (Discover IDP Authentications):
Enables a service provider to discover
whether a user has authenticated to a trusted identity provider, so the user can use single sign-
on without requiring authentication credentials.
Service domain:
The shared, common domain for all providers in the circle of trust. This
domain must resolve to the same IP address as the base URL domain. You must enable the
Identity Consumer
option to enable this field.
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...