220
Novell Access Manager 3.1 SP2 Identity Server Guide
n
ov
do
cx (e
n)
16
Ap
ril 20
10
https://idp.sitea.novell.com:8443/nidp/saml/idpsend?PID=https://
idp.siteb.novell.com:8443/nidp/saml/metadata&TARGET=https://
idp.siteb.novell.com:8443/nidp/app
The following happens when this link is invoked:
1. The browser performs a Get to the identity provider (Site A).
2. If the identity provider (Site A) trusts the service provider (Site B), the identity provider
prompts the user for authentication information and builds an assertion.
3. The identity provider (Site A) sends the user to the service provider (Site B), using the POST or
Artifact method.
4. The service provider (Site B) consumes the assertion and sends the user to the TARGET URL
(the user portal on Site B).
To configure the settings for the intersite transfer service, see
Section 7.10.2, “Modifying the
Authentication Card for SAML 1.1,” on page 216
.
7.11.3 Using Intersite Transfer Service Links on Web Pages
The Intersite Transfer Service URL can be used on a Web page that provides links to various
protected resources requiring authentication with a specific identity provider and a specific protocol.
Links on this Web page are configured with the URL of the Intersite Transfer Service of the identity
provider to be used for authentication. Clicking these links directs the user to the appropriate
identity provider for authentication. Following successful authentication, the identity provider sends
a SAML assertion to the service provider. The service provider uses the SAML assertion to verify
authentication, and then redirects the user to the destination URL as specified in the TARGET
portion of the Intersite Transfer Service URL.
Below are sample links that might be included on a Web page. These links demonstrate the use of
SAML 1.1, SAML 2.0, and Liberty formats for the Intersite Transfer Service URL:
SAML 1.1:
<a href="https://idp.sitea.novell.com:8443/nidp/saml/
idpsend?PID=https://idp.siteb.novell.com:8443/nidp/saml/
metadata&TARGET=https://eng.provo.novell.com/saml1/myapp">SAML1 example</a>
SAML 2.0:
<a href="https://idp.sitea.novell.com:8443/nidp/saml2/
idpsend?PID=https://idp.siteb.novell.com:8443/nidp/saml2/
metadata&TARGET=https://eng.provo.novell.com/saml2/myapp">SAML2 example</a>
Liberty:
<a href="https://idp.sitea.cit.novell.com:8443/nidp/idff/
idpsend?PID=https://idp.siteb.novell.com:8443/nidp/idff/
metadata&TARGET=https://eng.provo.novell.com/liberty/myapp">Liberty example</
a>
Figure 7-5
illustrates a network configuration that could use these sample links.
Содержание ACCESS MANAGER 3.1 SP2 - README 2010
Страница 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...