240
Novell Access Manager 3.1 SP2 Identity Server Guide
n
ov
do
cx (e
n)
16
Ap
ril 20
10
For a basic set up, see
Section 8.3.2, “Authenticating with a Managed Card,” on page 230
.
8.5.1 Replacing the Signing Certificate
For CardSpace and managed cards, you need to make sure that the SSL certificate and the signing
certificate of the Identity Server use the same name for the certificate’s subject name. When you
configured the Identity Server for SSL, you replaced the default SSL certificate with a certificate
that uses the DNS name of the Identity Server as the common name in the subject name of the
certificate. For CardSpace, you need to replace the default signing certificate. You can use the same
certificate for signing as you did for SSL or you can use different certificate, if the full subject name
is the same as the certificate you have configured for SSL.
1
In the Administration Console, click
Devices
>
Identity Servers
>
Edit
>
Security
.
2
In the
Keys and Certificate
section, click
Signing
.
3
Click
Replace
.
4
In the Replace pop-up, click the
Select Certificate
icon, select the certificate with the correct
subject name, then click
OK
.
5
When the certificate appears in the
Certificate
box, click
OK
, then click
Close
.
6
Update the Identity Server.
8.5.2 Configuring STS
CardSpace relies on the Security Token Service (STS), which controls what claims are available,
what authentication method can be used to validate the credentials on the card, and whether a name
identifier is added to the SAML assertion.
1
In the Administration Console, click
Devices
>
Identity Servers
>
Edit
>
STS
.
2
Verify that the CardSpace attribute set is listed in the
Attribute sets
list.
The CardSpace attribute set is a default set that ships with Access Manager. It contains all the
claims that can be sent with an authentication card.
3
Click
Authentication Methods
.
4
Select a method, move it to the
Methods
list, then click
Apply
.
The PasswordClass understands how to retrieve a name and password from a managed card. A
method created from this class must be installed at the STS to provide authentication for the
managed card. We recommend that you create a customized method from this class for
CardSpace. For information on how to create methods, see
Section 3.3, “Configuring
Authentication Methods,” on page 122
.
If you are using the
Secure Name/Password - Form
method, you can select this method because
it is created from PasswordClass.
If you have installed a custom class that can retrieve CardSpace credentials and you have
created a method for this class, you can select this method. For information on creating a
custom authentication class, see
Novell Access Manager Developer Tools and Examples
(http:/
/developer.novell.com/wiki/index.php/
Novell_Access_Manager_Developer_Tools_and_Examples)
.
5
Click
Apply
, then click
Authentication Request
.
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...