232
Novell Access Manager 3.1 SP2 Identity Server Guide
n
ov
do
cx (e
n)
16
Ap
ril 20
10
3
Click
New Card
, then click the
Managed Card Templat
e.
The card displays the required claims.
4
Specify a name for the card, then click
Create Card
.
5
Click
Open.
CardSpace opens.
6
Click
Install and Exit
.
The managed card is installed.
7
Log out and close the browser.
8
Continue with
“Configuring the Relying Party to Trust an Identity Provider” on page 232
.
Configuring the Relying Party to Trust an Identity Provider
A trusted provider is an issuer of authentication tokens that you want to strongly trust. The provider
has given you its issuer ID and its public key for the signing certificate. Tokens issued from this
trusted provider are validated by using the public key certificate.
To configure a trusted relationship between the relying party and the identity provider, you need to
create a trusted provider configuration for the identity provider. You also need to either modify an
existing authentication profile or create a profile that includes the trusted provider as an issuer of
security tokens.
To create a trusted provider configuration for the Identity Server acting as the identity provider, you
need to know the base URL of the Identity Server and have a file containing the public key of the
signing certificate of the Identity Server.
1
To obtain the public key certificate of the identity provider:
1a
Log in to the Administration Console of the identity provider.
1b
Click
Security
>
Certificates
.
1c
Click the certificate you have created for the Identity Server to use for SSL and signing.
1d
On the certificate page, click
Export Public Certificate
>
DER File
, then save the
certificate to a file.
1e
Copy this file to a location available to the Administration Console for the relying party.
2
To create a trusted provider configuration for the identity provider:
2a
Log in to the Administration Console for the relying party.
2b
Click
Devices
>
Identity Servers
>
Edit
>
CardSpace
.
2c
Click
Trusted Providers
>
New
, then fill in the following fields:
Name:
Specify a display name for the identity provider. This name appears in the list of
trusted providers that you can select for an authentication card profile. You might want to
use part of the DNS name of the identity provider.
Source:
This line specifies that the Provider ID is entered manually.
Provider ID:
Specify the issuer ID of the trusted provider. For an Identity Server cluster
configuration, the issuer ID is the base URL of the Identity Server plus the following path:
/sts/services/Trust
For example, if the base URL is
https://test.lab.novell.com:8443/nidp
, the
Provider ID is the following value:
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...