Previous Topic: Proxy Mode

Next Topic: Federation Manager Deployment with SiteMinder

Standalone Mode

In a standalone mode deployment, Federation Manager handles only federated requests, redirecting these requests to the target web servers. Non-federated requests go directly to the appropriate web server, independent of Federation Manager.

The advantage of standalone mode is that it limits federation traffic to Federation Manager and off-loads the handling of other content to other web servers. It also enables a site to add federation to its network without disrupting existing infrastructure.

In standalone mode you cannot pass user attributes from an assertion using HTTP headers because there is no proxy between the web server and the browser to add HTTP headers to the response.

The following figure shows a typical standalone mode deployment from the perspective of the relying party.

FM--Standalone Mode Architecture

The previous figure shows the following communication flow at the relying party:

  1. A user requests a federated resource.
  2. Based on the data in the assertion, Federation Manager authenticates the user, which includes communicating with the user directory to complete the user disambiguation process.
  3. Federation Manager returns a redirect response back to the user's browser.
  4. The browser redirects the user to the target resource on the target web server without having to pass through Federation Manager.


Copyright © 2010 CA. All rights reserved. Email CA about this topic