268
Novell Access Manager 3.1 SP2 Identity Server Guide
n
ov
do
cx (e
n)
16
Ap
ril 20
10
10.3 Managing WS Federation Providers
The WS Federation page allows you to create or edit trusted identity providers and trusted service
providers. When you create an identity provider configuration, you are configuring the Identity
Server to be a WS Federation resource partner. When you create a service provider configuration,
you are configuring the Identity Server to be a WS Federation account partner.
1
In the Administration Console, click
Devices > Identity Servers > Edit > WS Federation
.
2
Select one of the following actions:
New:
Launches the Create Trusted Identity Provider Wizard or the Create Trusted Service
Provider Wizard, depending on your selection. For more information, see one of the following:
Section 10.3.1, “Creating an Identity Provider for WS Federation,” on page 268
Section 10.3.2, “Creating a Service Provider for WS Federation,” on page 269
Delete:
Allows you to delete the selected identity or service provider. This action deletes the
definition.
Enable:
Enables the selected identity or service provider.
Disable:
Disables the selected identity or service provider. When the provider is disabled, the
server does not load the definition. However, the definition is not deleted.
Modify:
Click the name of a provider. For configuration information, see
Section 10.4,
“Modifying a WS Federation Identity Provider,” on page 269
or
Section 10.5, “Modifying a
WS Federation Service Provider,” on page 273
.
3
Click
OK
, then update the Identity Server.
10.3.1 Creating an Identity Provider for WS Federation
In order to have a trust relationship, you need to set up the ADFS server as an identity provider for
the Identity Server.
1
In the Administration Console, click
Devices
>
Identity Servers
>
Edit
>
WS Federation
.
2
On the WS Federation page, click
New
, select
Identity Provider
, then fill in the following
fields:
Name:
Specify a name that identifies the identity provider, such as
Adatum
.
Provider ID:
Specify the federation service URI of the identity provider, for example
urn:federation:adatum
.
Sign-on URL:
Specify the URL for logging in, such as
https://
adfsaccount.adatum.com/adfs/ls
/.
Logout URL:
Specify the URL for logging out, such as
https://
adfsresource.treyresearch.net/adfs/ls/
Identity Provider:
Specify the path to the signing certificate of the ADFS server.
3
Confirm the certificate, then click
Next
.
4
For the authentication card, specify the following values:
ID:
Leave this field blank.
Text:
Specify a description that is available to the user when the user mouses over the card.
Image:
Select an image, such as
Customizable
, or any other image.
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...