44
Novell Access Manager 3.1 SP2 Identity Server Guide
n
ov
do
cx (e
n)
16
Ap
ril 20
10
2. The Access Gateway redirects the user to the Identity Server, which prompts the user for a
username and password.
3. The Identity Server authenticates the user. If signing is enabled, the payload is signed by the
netHSM server through the Java JSSE security provider.
4. The Identity Server returns the authentication artifact to the Access Gateway.
5. The Embedded Service Provider of the Access Gateway retrieves the user’s credentials from
the Identity Server.
6. The Access Gateway verifies that the credentials allow the user access to the resource, then
sends the request to the Web server.
7. The Web server returns the requested Web page.
1.6.2 Configuring the Identity Server for netHSM
“Prerequisites for Using netHSM” on page 44
“Configuring the Identity Server to Be a netHSM Client” on page 44
“Creating the nCipher Signing Key Pair” on page 46
“Configuring the Identity Server to Use the netHSM Certificate” on page 51
“Verifying the Use of the nCipher Key Pair” on page 55
“Troubleshooting the netHSM Configuration” on page 56
Prerequisites for Using netHSM
An installed and configured netHSM server.
An installed and configured remote file system with the netHSM client.
An installed Identity Server, assigned to a cluster configuration.
For instructions on a basic setup that assigns the Identity Server to a cluster configuration, see
“
Creating a Basic Identity Server Configuration
” in the
Novell Access Manager 3.1 SP2 Setup
Guide
.
The following instructions describe one way to integrate the Identity Server with a netHSM server.
Other ways are possible.
Configuring the Identity Server to Be a netHSM Client
The following instructions are based on nCipher hardware, but you should be able to adapt them for
your hardware. The instructions explain how to configure the Identity Server so that it can
communicate with both the nCipher server and the remote file system server, how to create a signing
key pair and its keystore, how to copy these them to the Identity Server, and how to synchronize the
changes with the remote file system server.
1
At the Identity Server, log in as the root or administrator user and install the netHSM client
software.
The nCipher software installs files in the
/opt/nfast
directory on Linux and in the
C:\nfast
directory on Windows. It creates an nfast user and group. Check your netHSM documentation
for the specific steps.
2
(Conditional) If your Identity Server cluster configuration contains more than one Identity
Server, install the netHSM client software on the other Identity Servers in the cluster.
Содержание ACCESS MANAGER 3.1 SP2 - README 2010
Страница 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...