Previous Topic: Require User Consent at the SP

Next Topic: Single Logout (SAML 2.0)


Back Channel Authentication for Artifact SSO

Artifact single sign-on requires the relying party to send an artifact to the asserting party to retrieve the assertion. The asserting party uses the artifact to retrieve the correct assertion and returns the assertion to the relying party over a back channel.

You can require an entity to authenticate to access the back channel. The back channel can also be secured using SSL, though SSL is not required.

Securing the back channel using SSL involves:

To configure back channel authentication

  1. Begin at the Back Channel section in the SSO and SLO step of the Partnership wizard.
  2. Select HTTP-Artifact in the SSO section.

    The Authentication Method field becomes active.

  3. Select the type of authentication method for the incoming or outgoing back channel, or both.

    Note: Click Help for a description of fields, controls, and their respective requirements.

    If you select No Auth as the authentication method, no additional steps are required.

  4. Depending on the authentication method you select, several additional fields are displayed for you to configure.

    Note: Click Help for a description of fields, controls, and their respective requirements.

    The client certificate authentication method requires an X.509 client certificate to establish a connection. The relying party must have the key/certificate pair or client certificate authentication fails. Verify that the client certificate exists in the certificate data store at the asserting party. When the relying party sends the request for the assertion, the client certificate serves as the relying party credentials to access the retrieval service.

After entering values for all the necessary fields, the back channel configuration is complete. Enable SSL on each side of the connection for added security.

More information:

Partnership Creation