Configuring SAML and Liberty Trusted Providers
217
n
ov
do
cx (e
n)
16
Ap
ril 20
10
2
Modify the values in one or more of the following fields:
ID:
If you have need to reference this card outside of the user interface, specify an
alphanumeric value here. If you do not assign a value, the Identity Server creates one for its
internal use. The internal value is not persistent. Whenever the Identity Server is rebooted, it
can change. A specified value is persistent.
Text:
Specify the text that is displayed on the card to the user. This value, in combination with
the image, should identify to the users, which provider they are logging into.
Login URL:
Specify an Intersite Transfer Service URL.The URL has the following format,
where idp.sitea.novell.com is the DNS name of the identity provider, idp.siteb.novell.com is
the name of the service provider, and idp.siteb.novell.com:8443/nidp/app specifies the URL
that you want to users to access after a successful login:
https://idp.sitea.novell.com:8443/nidp/saml/idpsend?PID=https://
idp.siteb.novell.com:8443/nidp/saml/metadata&TARGET=https://
idp.siteb.novell.com:8443/nidp/app
For more information, see
“Specifying the Intersite Transfer Service URL for the Login URL
Option” on page 219
.
If your identity provider is a Novell Identity Server and you know the ID specified for the
target, you can use the following simplified format for the Login URL:
<URL for site a>
?id=
<ID of target>
For example:
https://idp.sitea.novell.com:8443/nidp/saml/idpsend?id=206test
The target and the target ID are specified in the service provider configuration at the identity
provider. See
“Configuring an Intersite Transfer Service Target for a Service Provider” on
page 221
.
Image:
Specify the image to be displayed on the card. Select the image from the drop-down
list. To add an image to the list, click
<Select local image>
.
Show Card:
Determine whether the card is shown to the user, which allows the user to select
and use the card for authentication. If this option is not selected, the card is only used when a
service provider makes a request for the card.
3
Click
OK
twice, then update the Identity Server.
7.11 Using the Intersite Transfer Service
Section 7.11.1, “Understanding the Intersite Transfer Service URL,” on page 217
Section 7.11.2, “Specifying the Intersite Transfer Service URL for the Login URL Option,” on
page 219
Section 7.11.3, “Using Intersite Transfer Service Links on Web Pages,” on page 220
Section 7.11.4, “Configuring an Intersite Transfer Service Target for a Service Provider,” on
page 221
7.11.1 Understanding the Intersite Transfer Service URL
The Intersite Transfer Service is used by an identity provider to cause authentication to occur at a
service provider that it trusts. The URLs for accessing the Intersite Transfer Service are different for
each supported protocol (Liberty, SAML 1.1, and SAML 2.0). The Novell Access Manager identity
and service provider components use the following format of the Intersite Transfer Service URL:
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...