Configuring WS Federation
263
n
ov
do
cx (e
n)
16
Ap
ril 20
10
“Enabling the STS and WS Federation Protocols” on page 263
“Creating a WS Federation Identity Provider” on page 263
“Modifying the User Identification Specification” on page 264
“Importing the ADFS Signing Certificate into the NIDP-Truststore” on page 265
Prerequisites
You have set up the Active Directory Federation Services, Active Directory, and SharePoint
servers and the client as described in the ADFS guide from Microsoft. See the “
Step-by-Step
Guide for Active Directory Federation Services” (http://go.microsoft.com/fwlink/
?linkid=49531)
.
You have set up the Novell Access Manager 3.1 system with a site configuration that is using
SSL in the Identity Server's base URL. See “
Enabling SSL Communication
” in the
Novell
Access Manager 3.1 SP2 Setup Guide
.
Enable the Liberty Personal Profile.
In the Administration Console, click
Identity Servers
>
Edit
>
Liberty
>
Web Service Provider
.
Select the
Personal Profile
, then click
Enable
>
Apply
. Update the Identity Server.
Enabling the STS and WS Federation Protocols
Access Manager ships with only SAML 1.1, Liberty, and SAML 2.0 enabled by default. In order to
use the WS Federation protocol, it must be enabled on the Identity Server. Because the WS
Federation Protocol uses the STS (Secure Token Service) protocol, STS must also be enabled.
1
In the Administration Console, click
Devices
>
Identity Servers
>
Edit
.
2
In the
Enabled Protocols
section of the General Configuration page, enable the STS and WS
Federation protocols.
3
Click
OK
.
4
Update the Identity Server.
5
Continue with
“Creating a WS Federation Identity Provider” on page 263
.
Creating a WS Federation Identity Provider
In order to have a trust relationship, you need to set up the Adatum site (adfsaccount.adatum.com) as
an identity provider for the Identity Server.
Adatum is the default name for the identity provider. If you have used another name, substitute it
when following these instructions. To create an identity provider, you need to know the following
information about the Adatum site:
Table 10-2
Adatum Values
What You Need to Know Default Value and Description
Provider ID
Default Value:
urn:federation:adatum
The ADFS server provides this value to the service provider in the realm
parameter in the assertion. You set this value in the
Properties
of the Trust
Policy on the ADFS server. The label is
Federation Service URI
.
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...