214
Novell Access Manager 3.1 SP2 Identity Server Guide
n
ov
do
cx (e
n)
16
Ap
ril 20
10
2
Select the binding method.
If the request from the service provider does not specify a response binding, you need to
specify a binding method to use in the response. Select
Artifact
to provide an increased level of
security by using a back-channel means of communication between the two servers. Select
Post
to use HTTP redirection for the communication channel between the two servers. If you select
Post
, you might want to require the signing of the authentication requests. See
Section 7.2.1,
“Configuring the General Identity Provider Options,” on page 186
.
3
Specify the identity formats that the Identity Server can send in its response. Select the box to
choose one or more of the following:
Persistent:
Specifies that a persistent identifier, which is written to the directory and
remains intact between sessions, can be sent.
Transient:
Specifies that a transient identifier, which expires between sessions, can be
sent.
E-mail:
Specifies that an e-mail attribute can be used as the identifier.
Kerberos:
Specifies that a Kerberos token can be used as the identifier.
X509:
Specifies that an X.509 certificate can be used as the identifier.
Unspecified:
Specifies that an unspecified format can be used and any value can be used.
The service provider and the identity provider need to agree on the value that is placed in
this identifier.
4
Use the
Default
button to select the name identifier that the Identity Server should send if the
service provider does not specify a format.
If you select E-mail, Kerberos, x509, or unspecified as the default format, you should also
select a value. See
Step 5
.
IMPORTANT:
If you have configured the identity provider to allow a user matching
expression to fail and still allow authentication by selecting the
Do nothing
option, you need to
select
Transient identifier format
as the default value. Otherwise the users who fail the
matching expression are denied access. To view the identity provider configuration, see
“Defining User Identification for Liberty and SAML 2.0” on page 277
.
5
Specify the value for the name identifier.
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...