Configuring WS Federation
255
n
ov
do
cx (e
n)
16
Ap
ril 20
10
2
Move the WS Federation attribute set to the
Attribute set
list.
3
Select the WS Federation attribute set and use the up-arrow to make it first in the
Attribute set
list.
4
Click
OK
, then update the Identity Server.
Creating a WS Federation Service Provider
In order to establish a trusted relationship with the ADFS server, you need to set up the Trey
Research site as a service provider. The trusted relationship allows the service provider to trust the
Identity Server for user authentication credentials.
Trey Research is the default name for the ADFS resource server. If you have used another name,
substitute it when following these instructions. To create a service provider, you need to know the
following about the ADFS resource server.
Table 10-1
ADFS Resource Server Information
To create a service provider configuration:
1
On the Identity Servers page, click
Edit
>
WS Federation
.
2
Click
New
>
Service Provider
, then fill in the following fields:
Name:
Specify a name that identifies the service provider, such as
TreyResearch
.
What You Need to Know
Default Value and Description
Provider ID
Default Value:
urn:federation:treyresearch
This is the value that the ADFS server provides to the Identity Server in the
realm parameter of the query string. This value is specified in the Properties of
the Trust Policy page on the ADFS server. The parameter label is
Federation
Service URI
.
Sign-on URL
Default Value:
https://adfsresource.treyresearch.net/adfs/ls/
This is the value that the identity provider redirects the user to after login.
Although it is listed as optional, and is optional between two Novell Identity
Servers, the ADFS server doesn't send this value to the identity provider. It is
required when setting up a trusted relationship between an ADFS server and a
Novell Identity Server.
This URL is listed in the Properties of the Trust Policy page on the ADFS
server. The parameter label is
Federation Services endpoint URL
.
Logout URL
Default Value:
https://adfsresource.treyresearch.net/adfs/ls/
This parameter is optional. If it is specified, the user is logged out of the ADFS
server and the Identity Server.
Signing Certificate
This is the certificate that the ADFS server uses for signing.
You need to export it from the ADFS server. It can be retrieved from the
properties of the
Trust Policy
on the ADFS Server on the
Verification
Certificates
tab.
This certificate is a self-signed certificate that you generated when following
the Active Directory step-by-step guide.
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...