Configuring WS Federation
269
n
ov
do
cx (e
n)
16
Ap
ril 20
10
Show Card:
Enable this option so that the card can be presented to the user as a login option.
5
Click
Finish
.
For information about additional configuration steps required to use this identity provider, see
Section 10.2, “Using the ADFS Server as an Identity Provider for an Access Manager Protected
Resource,” on page 262
.
10.3.2 Creating a Service Provider for WS Federation
In order to establish a trusted relationship with the ADFS server, you need to set up the ADFS server
as service provider. The trusted relationship allows the service provider to trust the Identity Server
for user authentication credentials.
1
In the Administration Console, click
Devices
>
Identity Servers
>
Edit
>
WS Federation
.
2
Click
New
>
Service Provider
, then fill in the following fields:
Name:
Specify a name that identifies the service provider, such as
TreyResearch
.
Provider ID:
Specify the provider ID of the ADFS server. The default value is
urn:federation:treyresearch
.
Sign-on URL:
Specify the URL that the user is redirected to after login. The default value is
https://adfsresource.treyresearch.net/adfs/ls/
.
Logout URL:
(Optional) Specify the URL that the user can use for logging out. The default
value is
https://adfsresource.treyresearch.net/adfs/ls
.
Service Provider:
Specify the path to the signing certificate of the ADFS server.
3
Click
Next
, confirm the certificate, then click
Finish
.
For information about additional configuration steps required to use this service provider, see
Section 10.1, “Using the Identity Server as an Identity Provider for ADFS,” on page 251
.
10.4 Modifying a WS Federation Identity Provider
This section explains how to modify a WS Federation identity provider after it has been created.
Section 10.3.1, “Creating an Identity Provider for WS Federation,” on page 268
explains the steps
required to create an identity provider. You can modify the following configuration details:
Section 10.4.1, “Renaming the Trusted Provider,” on page 269
Section 10.4.2, “Configuring the Attributes Obtained at Authentication,” on page 270
Section 10.4.3, “Modifying the User Identification Method,” on page 270
Section 10.4.4, “Viewing the WS Identity Provider Metadata,” on page 271
Section 10.4.5, “Editing the WS Identity Provider Metadata,” on page 272
Section 10.4.6, “Modifying the Authentication Card,” on page 272
10.4.1 Renaming the Trusted Provider
1
In the Administration Console, click
Devices > Identity Servers > Edit > WS Federation >
[Provider Name].
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...