Troubleshooting the Identity Server and Authentication
351
n
ov
do
cx (e
n)
16
Ap
ril 20
10
3
Click
Edit
>
Reverse Proxies/Authentication
.
4
Select an Identity Server configuration for the
Identity Server Cluster
option, click
OK
twice,
then update the Access Gateway.
Service Provider Metadata
If you have set up federation with another provider over the Liberty, SAML 1.1, SAML 2.0,
CardSpace, or WS Federation protocol and you change the base URL of the Identity Server, you
need to update the provider with the new metadata to reestablish the trusted relationship. If the
provider is another Identity Server, follow the procedure below to update the metadata; otherwise,
follow the provider’s procedures.
1
In the Administration Console of the provider, click
Devices
>
Identity Servers
>
Edit
>
[Protocol]
>
[Provider]
>
Metadata
.
2
Click
Reimport
.
3
Follow the steps in the wizard.
For more information, see
Section 7.7, “Managing Metadata,” on page 203
.
15.2.2 DNS Name Resolution
When the service provider tries to access the metadata on the identity provider, it sends the request
to the hostname defined in the base URL configuration of the Identity Server. The base URL in the
Identity Server configuration is used to build all the metadata end points.
To view the metadata of the Identity Server with a DNS name of
idpcluster.lab.novell.com
,
enter the following URL:
https://idpcluster.lab.novell.com:8443/nidp/idff/metadata
Scan through the document and notice the multiple references to
https://
idpcluster.lab.novell.com/..
. You should see lines similar to the following:
<md:SoapEndpoint>
https://idpcluster.lab.novell.com:8443/nidp/idff/soap
</md:SoapEndpoint>
<md:SingleLogoutServiceURL>
https://idpcluster.lab.novell.com:8443/nidp/idff/slo
</md:SingleLogoutServiceURL>
<md:SingleLogoutServiceReturnURL>
https://idpcluster.lab.novell.com:8443/nidp/idff/slo_return
</md:SingleLogoutServiceReturnURL>
The Embedded Service Provider of the Access Gateway must be able to resolve the
idpcluster.lab.novell.com
hostname of the Identity Server. To test that it is resolvable, send a
ping
command with the hostname of the Identity Server. For example, from the Access Gateway:
ping idpcluster.lab.novell.com
Содержание ACCESS MANAGER 3.1 SP2 - README 2010
Страница 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...