Previous Topic: HTTP Header Protection for a Proxy Mode Deployment at the Relying Party

Next Topic: Cookie Settings for Session and Identity Cookies


SiteMinder Connector Settings

The SiteMinder Connector lets Federation Manager integrate with a SiteMinder environment for federated communication.

At the asserting party, the SiteMinder Connector can work with SiteMinder as a third-party WAM for delegated authentication. At the relying party, SiteMinder can protect the server where the target resources reside. If SiteMinder is performing access control, the SiteMinder Connector contacts the Policy Server to establish a SiteMinder session so that SiteMinder grants the user access to the target resource.

For Federation Manager to operate with SiteMinder, configure the SiteMinder Connector settings in the Federation Manager UI.

All partnerships that use the SiteMinder Connector use a single configuration and connect to a single SiteMinder environment. Define the Connector configuration in the Deployment Settings of the Federation Manager UI. To enable the Connector for a given partnership, enable it at the partnership level. Disable the Connector at the partnership level or globally by disabling it in the Deployment Settings.

Important! If the Connector is disabled at the global level, Federation Manager ignores the check box at the partnership level.

To configure the SiteMinder Connector

  1. Log in to the Federation Manager UI.
  2. Select a partnership from the Federated Partnerships list.

    The Partnership dialog opens.

  3. Do one of the following:
    1. At the relying party, navigate to the User Identification step in the Partnership wizard.
    2. At the asserting party, navigate to the Federation Users step in the Partnership wizard.
  4. Select the Enable SiteMinder Connector check box.

    The configuration fields become available.

  5. (Optional) Select the Enforce UserDN Comparison check box. Selecting this check box forces a comparison of the UserDN and UserDirectory Name entries between the user directory at Federation Manager and the directory at SiteMinder.

    If you select this check box, the user directory for the Federation Manager deployment and the SiteMinder deployment must be the same physical directory. The name for both of these directories must be the same for user store lookups. If you clear the check box, Federation Manager uses the Universal ID to find the user record so the directories do not have to be the same. If you rely on the Universal ID, each user must have a unique Universal ID. If the Universal IDs are not unique, the system accessing the user record can retrieve the wrong record.

  6. Save your changes.
  7. Navigate to the Infrastructure tab.
  8. From the Infrastructure tab, select Deployment Settings.

    The Configure Deployment Settings dialog opens.

  9. Fill in all the fields in the SiteMinder Connector Settings section.

    Note: Click Help for a description of fields, controls, and their respective requirements.

  10. Select Register Host and provide the administrator credentials for the SiteMinder Policy Server.

    This step registers Federation Manager as an Agent with the SiteMinder Policy Server.

    Note: You can configure failover support for the host registration process by specifying more than one Policy Server. If the registration with the primary Policy Server fails, Federation Manager moves to the next Policy Server specified until the registration process completes successfully.

  11. Select Save in the SiteMinder Connector Settings section of the dialog.

    Selecting Save in the SiteMinder Connector Settings section is necessary after registering the host.

  12. Restart the federation services according to your operating environment.

The SiteMinder Connector configuration is complete.