248
Novell Access Manager 3.1 SP2 Identity Server Guide
n
ov
do
cx (e
n)
16
Ap
ril 20
10
3
Select one of the following user identification methods for associating the accounts:
Do nothing:
Allows the user to authenticate without creating an association with a user
account. This option cannot be used when federation is enabled.
Authenticate:
Select this option when you want to use login credentials. This option
prompts the user to log in to the service provider.
Allow ‘Provisioning’:
Select this option to allow users to create an account when
they have no account on the service provider.
This option requires that you specify a user provisioning method.
Provision Account:
Select this option when the users on the identity provider do not have
accounts on the service provider. This option allows the service provider to trust any user
that has authenticated to the trusted identity provider.
This option requires that you specify a user provisioning method.
Attribute matching:
Select this option when you want to use attributes to match an
identity server account with a service provider account. This option requires that you
specify a user matching method.
Prompt for password on successful match:
Select this option to prompt the user
for a password when the user’s name is matched to an account, to ensure that the
account matches.
4
(Conditional) If you selected a user identification method that requires a matching method or a
provision setting, configure the required method.
Provisioning Settings:
Allows you to select or create a user provisioning method. See
Section 11.3, “Defining the User Provisioning Method,” on page 282
. For user provisioning
error messages, see
Section 11.4, “User Provisioning Error Messages,” on page 286
.
Attribute Matching Settings:
Allows you to select or create a user matching method. See
Configuring the Attribute Matching Method for Liberty or SAML 2.0
.
5
If you are creating a new profile, click
Finish
, or if you are modifying a profile, click
OK
.
6
Click
OK
, then update the Identity Server.
8.10 Cleaning Up Identities
Use the Configuration page to manage time limits for identity cleanup.
1
In the Administration Console, click
Devices
>
Identity Servers
>
Edit
>
CardSpace
>
Configuration
.
2
Configure the following fields:
Maximum Age (for Unused Identities):
Specifies how long an account can remain inactive
before the account is defederated. The default limit is 90 days. Specify a value from 0 to 365
days.
Maximum Age (for Managed Cards Backed by Personal Cards):
Specifies how long a
managed card, backed by a personal card, can remain valid without the token being refreshed.
When this limit is reached, the managed card is deleted. The default limit is 90 days. Specify a
value from 0 to 365 days.
3
Click
OK
, then update the Identity Server if you have changed the configuration.
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...