Configuring SAML and Liberty Trusted Providers
213
n
ov
do
cx (e
n)
16
Ap
ril 20
10
If the request from the service provider does not specify a response binding, you need to
specify a binding method to use in the response. Select
Artifact
to provide an increased level of
security by using a back-channel means of communication between the two servers. Select
Post
to use HTTP redirection for the communication channel between the two servers. If you select
Post
, you might want to require the signing of the authentication requests. See
Section 7.2.1,
“Configuring the General Identity Provider Options,” on page 186
.
3
Specify the identity formats that the Identity Server can send in its response. Select the
Use
box
to choose one or more of the following:
Persistent Identifier Format:
Specifies that a persistent identifier, which is written to the
directory and remains intact between sessions, can be sent.
Transient Identifier Format:
Specifies that a transient identifier, which expires between
sessions, can be sent.
If the request from the service provider requests a format that is not enabled, the user cannot
authenticate.
4
Use the
Default
button to specify whether a persistent or transient identifier is sent when the
request from the service provider does not specify a format.
5
To specify that this Identity Server must authenticate the user, disable the
Use proxied requests
option. When the option is disabled and the Identity Server cannot authenticate the user, the
user is denied access.
When this option is enabled, the Identity Server checks to see if other identity providers can
satisfy the request. If one or more can, the user is allowed to select which identity provider
performs the authentication. If a proxied identity provider performs the authentication, it sends
the response to the Identity Server. The Identity Server then sends the response to the service
provider.
6
Enable the
Provide Discovery Services
option if you want to allow the service provider to query
the Identity Server for a list of its Web Services. For example, when the option is enabled, the
service provider can determine whether the Web Services Framework is enabled and which
Web Service Provider profiles are enabled.
7
Click
OK
twice, then update the Identity Server.
7.9.2 Configuring the SAML 2.0 Authentication Response
After you create a trusted service provider, you can configure how your Identity Server responds to
authentication requests from the service provider.
1
In the Administration Console, click
Devices > Identity Servers > Edit > SAML 2.0 > [Service
Provider] > Authentication Response
.
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...