

Advanced Authentication Service › Getting Started with Advanced Authentication › Configuring Advanced Authentication › How to Configure Advanced Authentication › Configure and Apply an Authentication Scheme › Configure a Realm and a Rule for the Resource
Configure a Realm and a Rule for the Resource
A realm groups resources that have similar security requirements and share a common authentication scheme. In the tenant domain, create a realm for each authentication scheme that the tenant administrator wants to use.
Note: The following procedure assumes that you are creating an object. You can also copy the properties of an existing object to create an object.
Follow these steps:
- Log in to the CSP console.
- Select Policies, Domain, Realms.
The Realms screen opens.
- Click Create Realm.
- Select the tenant domain that you want to modify, and then click Next.
Note: The tenant domain name is in the tenant-tagDomain format.
- Type a name and description for the realm.
Specify a name that indicates that the realm is for an authentication URL.
- Click Lookup Agent/Agent Group.
- Select cam-agent from the list of agents, and then click OK.
- Specify the resource filter for the authentication scheme. This scheme must tie in to the authentication method chosen in the User Console.
- ArcotID OTP
-
/affwebservices/tenant_tag/arcototp.jsp
- ArcotID OTP with Risk
-
/affwebservices/tenant_tag/arcototprisk.jsp
- ArcotID PKI
-
/affwebservices/tenant_tag/arcotid.jsp
- ArcotID PKI with Risk
-
/affwebservices/tenant_tag/arcotidrisk.jsp
tenant_tag is a unique identifier for a tenant. You specify the tag when deploying a tenant environment in the CSP console. To view a list of tags, select the Tenants tab.
- Complete the remaining fields:
- Default Resource Protection
-
Protected
- Authentication Scheme
-
Select the authentication scheme that corresponds to the resource filter.
- Create a rule as follows:
- Click Create in the Rules area.
The Create Rule screen opens.
- Enter a name and description for the rule.
- Enter the asterisk (*) in the Resource field.
- Select Get and Post from the Action list.
- Accept the defaults for the remaining settings, and then click OK.
The rule is created.
- Specify the session properties.
Note: Click Help for information about these properties.
- Skip the other configuration options.
- Click Finish.
The realm is configured.
Copyright © 2013 CA.
All rights reserved.
 
|
|