Configuring SAML and Liberty Trusted Providers
203
n
ov
do
cx (e
n)
16
Ap
ril 20
10
7.7 Managing Metadata
The Liberty, SAML 1.1, and SAML 2.0 protocols contain pages for viewing and reimporting the
metadata of the trusted providers. Only the SAML 1.1 protocol allows you to edit the metadata.
Section 7.7.1, “Viewing and Reimporting a Trusted Provider’s Metadata,” on page 203
Section 7.7.2, “Viewing Trusted Provider Certificates,” on page 203
Section 7.7.3, “Editing a SAML 1.1 Identity Provider’s Metadata,” on page 204
Section 7.7.4, “Editing a SAML 1.1 Service Provider’s Metadata,” on page 205
7.7.1 Viewing and Reimporting a Trusted Provider’s Metadata
You might need to reimport a trusted provider’s metadata if you learn that it has changed. The
metadata changes when you change the provider to use HTTPS rather than HTTP and when you
change the certificate that it is using for SSL. The steps for reimporting the metadata are similar for
Liberty and SAML protocols.
1
In the Administration Console, click
Devices > Identity Servers > Edit > [Protocol]
.
2
Click the trusted provider, then click the
Metadata
tab.
This page displays the current metadata the trusted provider is using.
3
To reimport the metadata:
3a
Copy the URL in the providerID field (Liberty) or the entityID (SAML).
3b
(SAML 1.1) Paste the URL to a file, click
Authentication Card
, copy the
Login URL
to the
file, then click
Metadata
.
3c
Click
Reimport
.
3d
Follow the prompts to import the metadata.
For the metadata URL, paste in the value you copied.
If your Administration Console is installed with your Identity Server, you need to change
the protocol from HTTPS to HTTP and the port from 8443 to 8080.
4
Confirm metadata certificates, then click
Finish
, or for an identity provider, click
Next
.
5
(Identity Provider) Configure the card, then click
Finish
.
For SAML 1.1, copy the value you saved into the
Login URL
.
6
Update the Identity Server.
7.7.2 Viewing Trusted Provider Certificates
You can review and confirm the certificate information for identity and service providers.
1
In the Administration Console, click
Devices
>
Identity Servers > Edit > [Protocol] > [Name
of Provider] > Metadata > Certificates
.
2
View the following information is displayed for the certificates:
Subject:
The subject name assigned to the certificate.
Validity:
The first date the certificate was valid, and the date the certificate expires.
Содержание ACCESS MANAGER 3.1 SP2 - README 2010
Страница 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...