Previous Topic: Integrate with SiteMinder using the SiteMinder Connector

Next Topic: FIPS Compatibility in SiteMinder Connector Mode

How to Configure the SiteMinder Connector

The configuration process for the SiteMinder Connector is as follows:

  1. Configure a policy at the SiteMinder Policy Server whose purpose is to generate a SiteMinder session. Although this policy functions as any other SiteMinder policy, its main objective is to trigger a session, not to protect resources.

    The policy requires that you configure the typical SiteMinder objects that make up a policy; however, you use a custom SiteMinder authentication scheme.

    Note: This policy is in addition to existing policies that are configured for SiteMinder access control.

  2. Configure the SiteMinder Connector at Federation Manager.

    All partnerships that use the SiteMinder Connector use a single configuration and connect to a single SiteMinder environment. You define the Connector configuration in the Deployment Settings of the Federation Manager UI. To enable the Connector for a given partnership, enable it at the partnership level. Disable the Connector at the partnership level or globally by disabling it in the Deployment Settings.

    Important! If the Connector is disabled at the global level, Federation Manager ignores the check box at the partnership level.

  3. Register Federation Manager with SiteMinder as a SiteMinder Web Agent in the Federation Manager UI.
  4. Set up a working partnership between the asserting and relying parties.

At the partnership-level configuration for the SiteMinder Connector, there is an Enforce UserDN Comparison check box. If you leave this check box selected, the user directory for the Federation Manager deployment and the SiteMinder deployment must be the same physical directory. The name for both of these directories must be the same for user store lookups. If you clear the check box, Federation Manager uses the Universal ID to find the user record so the directories do not have to be the same. If you rely on the Universal ID, each user must have a unique Universal ID. If the Universal IDs are not unique, the system accessing the user record can retrieve the wrong record.

More information:

Configure a Policy at the SiteMinder Policy Server

Set up a Partnership with SiteMinder at the Relying Party