Contents
9
n
ov
do
cx (e
n)
16
Ap
ril 20
10
10.3.1
Creating an Identity Provider for WS Federation . . . . . . . . . . . . . . . . . . . . . . . . . . . 268
10.3.2
Creating a Service Provider for WS Federation. . . . . . . . . . . . . . . . . . . . . . . . . . . . 269
10.4 Modifying a WS Federation Identity Provider . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 269
10.4.1
Renaming the Trusted Provider. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 269
10.4.2
Configuring the Attributes Obtained at Authentication. . . . . . . . . . . . . . . . . . . . . . . 270
10.4.3
Modifying the User Identification Method. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 270
10.4.4
Viewing the WS Identity Provider Metadata . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 271
10.4.5
Editing the WS Identity Provider Metadata . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 272
10.4.6
Modifying the Authentication Card. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 272
10.5 Modifying a WS Federation Service Provider. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 273
10.5.1
Renaming the Service Provider . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 273
10.5.2
Configuring the Attributes Sent with Authentication. . . . . . . . . . . . . . . . . . . . . . . . . 273
10.5.3
Modifying the Authentication Response . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 274
10.5.4
Viewing the WS Service Provider Metadata . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 275
10.5.5
Editing the WS Service Provider Metadata . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 275
11 Configuring User Identification Methods for Federation
277
11.1 Defining User Identification for Liberty and SAML 2.0 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 277
11.1.1
Selecting a User Identification Method for Liberty or SAML 2.0 . . . . . . . . . . . . . . . 277
11.1.2
Configuring the Attribute Matching Method for Liberty or SAML 2.0 . . . . . . . . . . . . 279
11.2 Defining User Identification for SAML 1.1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 280
11.2.1
Selecting a User Identification Method for SAML 1.1 . . . . . . . . . . . . . . . . . . . . . . . 280
11.2.2
Configuring the Attribute Matching Method for SAML 1.1 . . . . . . . . . . . . . . . . . . . . 281
11.3 Defining the User Provisioning Method . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 282
11.4 User Provisioning Error Messages. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 286
12 Configuring Communication Profiles
287
12.1 Configuring a Liberty Profile. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 287
12.2 Configuring a SAML 1.1 Profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 288
12.3 Configuring a SAML 2.0 Profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 288
13 Configuring Liberty Web Services
291
13.1 Configuring the Web Services Framework. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 291
13.2 Managing Web Services and Profiles . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 292
13.2.1
Modifying Service and Profile Details for Employee, Custom, and Personal
Profiles. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 293
13.2.2
Modifying Details for Authentication, Discovery, LDAP, and User Interaction
Profiles. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 295
13.2.3
Editing Web Service Descriptions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 296
13.2.4
Editing Web Service Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 297
13.2.5
Create Web Service Type . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 300
13.3 Configuring Credential Profile Security and Display Settings. . . . . . . . . . . . . . . . . . . . . . . . . 300
13.4 Customizing Attribute Names. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 302
13.5 Configuring the Web Service Consumer . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 303
13.6 Mapping LDAP and Liberty Attributes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 304
13.6.1
Configuring One-to-One Attribute Maps . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 305
13.6.2
Configuring Employee Type Attribute Maps . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 308
13.6.3
Configuring Employee Status Attribute Maps . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 309
13.6.4
Configuring Postal Address Attribute Maps . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 311
13.6.5
Configuring Contact Method Attribute Maps . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 312
13.6.6
Configuring Gender Attribute Maps . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 314
13.6.7
Configuring Marital Status Attribute Maps . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 315
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...