When you configure single sign-on at the asserting party, you specify how the asserting party delivers an assertion to a relying party.
Note: Only one single sign-on session is persisted in a browser. The session information is stored in the FEDSESSION cookie. If you access another partnership in the same browser, the FEDSESSION cookie is not valid, unless the underlying user directory is the same as the previously accessed partnership during the same browser session.
To configure single sign-on at the asserting party
Single Sign-On
SSO and SLO
Note: You can click Help for a description of fields, controls, and their respective requirements.
Select Local or Delegated
Select Basic or Form based
If you are using Federation Manager that is localized for Japanese or French users, select Forms based authentication scheme. Basic authentication is not supported for localized users.
For forms authentication, sample log-in forms are available for Japanese and French. The forms are in the directory federation_mgr_home/secure-proxy/proxy-engine/examples in the folders formsja (Japanese) and formsfr (French).
To use the localized forms
Select Legacy Cookie, Query String, Open-format Cookie
Note: The open format cookie is the only FIPS-compatible option for delegated authentication.
If user identity information is being passed from the third-party WAM in a cookie, configure the Delegated Authentication URL. This URL redirects the request to the WAM system if the user comes to Federation Manager first. The URL does not apply when the user visits the WAM first.
If user identity information is being passed from the third-party WAM in a query string, configure the following settings:
This URL redirects the request to the WAM system when the user comes to Federation Manager first. The URL does not apply when user goes to the WAM first.
Open-format Cookie
If user identity information is being passed from the third-party WAM in a FIPS-encrypted cookie, configure the Delegated Authentication URL. The open format cookie is the only FIPS-compatible option for delegated authentication. This URL redirects the request to the WAM system if the user comes to Federation Manager first. The URL does not apply when user goes to the WAM first.
Note: If you select Legacy Cookie or Open-format Cookie as the Delegated Authentication Type, configure the required global cookie settings. Locate the deployment settings by navigating to Infrastructure, Deployment Settings.
Guidelines:
Be aware of the following guidelines:
Note: For artifact binding, the assertion is sent over a secure back channel. Therefore, configure the settings in the Back Channel group box.
Any values defined during the creation or import of the remote relying party are already filled in.
This procedure completes SSO configuration for the asserting party.
| Copyright © 2010 CA. All rights reserved. | Email CA about this topic |