The SiteMinder Connector lets Federation Manager integrate with a SiteMinder environment for federated communication.
At the asserting party, the SiteMinder Connector can work with SiteMinder as a third-party WAM for delegated authentication. At the relying party, SiteMinder can protect the server where the target resources reside. If SiteMinder is performing access control, the SiteMinder Connector contacts the Policy Server to establish a SiteMinder session so that SiteMinder grants the user access to the target resource.
For Federation Manager to operate with SiteMinder, configure the SiteMinder Connector settings in the Federation Manager UI.
All partnerships that use the SiteMinder Connector use a single configuration and connect to a single SiteMinder environment. Define the Connector configuration in the Deployment Settings of the Federation Manager UI. To enable the Connector for a given partnership, enable it at the partnership level. Disable the Connector at the partnership level or globally by disabling it in the Deployment Settings.
Important! If the Connector is disabled at the global level, Federation Manager ignores the check box at the partnership level.
To configure the SiteMinder Connector
The Partnership dialog opens.
The configuration fields become available.
If you select this check box, the user directory for the Federation Manager deployment and the SiteMinder deployment must be the same physical directory. The name for both of these directories must be the same for user store lookups. If you clear the check box, Federation Manager uses the Universal ID to find the user record so the directories do not have to be the same. If you rely on the Universal ID, each user must have a unique Universal ID. If the Universal IDs are not unique, the system accessing the user record can retrieve the wrong record.
The Configure Deployment Settings dialog opens.
Note: Click Help for a description of fields, controls, and their respective requirements.
This step registers Federation Manager as an Agent with the SiteMinder Policy Server.
Note: You can configure failover support for the host registration process by specifying more than one Policy Server. If the registration with the primary Policy Server fails, Federation Manager moves to the next Policy Server specified until the registration process completes successfully.
Selecting Save in the SiteMinder Connector Settings section is necessary after registering the host.
Use the stop and start shortcuts as follows. If you logged in as a network user and not a local administrator, right-click the shortcut and select Run as administrator.
a. Open a command window.
b. Run the following scripts:
federation_mgr_home/fedmanager.sh stop
federation_mgr_home/fedmanager.sh start
Note: Do not stop and start the services as the root user.
The SiteMinder Connector configuration is complete.
| Copyright © 2012 CA. All rights reserved. |
|