Configuring an Identity Server
29
n
ov
do
cx (e
n)
16
Ap
ril 20
10
To view your current configuration for the SOAP back channel:
1
In the Administration Console, click
Devices
>
Identity Servers
>
Edit
.
2
Select the protocol (Liberty, SAML 1.1, or SAML 2.0), then click the name of an identity
provider or service provider.
3
Click
Access
.
4
View the
Security
section. If the
Message Signing
option is selected, signing is enabled for the
SOAP back channel.
Profiles
Any of the Web Service Provider profiles can be enabled for signing by configuring them to use
X.509 for their message-level security mechanism.
To view your current configuration:
1
In the Administration Console, click
Devices
>
Identity Servers
>
Edit
>
Liberty
>
Web Service
Provider
.
2
Click the name of a profile, then click
Descriptions
.
3
Click the
Description Name
.
4
If either
Peer entity = None, Message=X509
or
Peer entity = MutualTLS, Message=X509
has
been selected as the security mechanism, signing has been enabled for the profile.
1.3.2 Viewing Services That Use the Encryption Key Pair
All of the Liberty Web Service Provider Profiles allow you to configure them so that the resource
IDs are encrypted. By default, no profile encrypts the IDs.
To view your current configuration:
1
In the Administration Console, click
Devices > Identity Servers > Edit
>
Liberty
>
Web Service
Provider
.
2
Click the name of a profile.
3
If the
Have Discovery Encrypt This Service’s Resource IDs
option is selected, the encryption
key pair is used to encrypt the resource IDs.
1.3.3 Managing the Keys, Certificates, and Trust Stores
You can view the private keys, CA certificates, and certificate containers associated with the Identity
Server configuration. Primarily, you use the Security page to add and replace CA certificates as
necessary and to perform certificate management tasks, such as adding trusted root certificates to a
trust store.
1
In the Administration Console, click
Devices > Identity Servers > Edit > Security
.
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...