Previous Topic: Assertion Validity for Single Sign-on

Next Topic: Single Logout (SAML 2.0)

Back Channel Authentication for Artifact SSO

Artifact single sign-on requires the relying party to send an artifact to the asserting party to retrieve the assertion. The asserting party uses the artifact to retrieve the correct assertion and then it returns the assertion to the relying party over a back channel, which is typically secured.

You can require an entity to authenticate to access the back channel. The back channel can also be secured using SSL, though SSL is not required.

Securing the back channel using SSL involves:

To configure back channel authentication

  1. Begin at the Back Channel group box in the SSO and SLO step of the Partnership wizard.
  2. Select HTTP-Artifact in the SSO group box.

    The Authentication Method field becomes active.

  3. Select the type of authentication method for the incoming and/or outgoing back channel.

    Note: You can click Help for a description of fields, controls, and their respective requirements.

    If you select No Auth as the authentication method, no additional steps are required.

  4. Depending on the authentication method you choose, several additional fields are displayed for you to configure.

    Note: You can click Help for a description of fields, controls, and their respective requirements.

After entering values for all the necessary fields, the back channel configuration is complete. You can enable SSL on each side of the connection for added security.

More information:

Partnership Creation


Copyright © 2010 CA. All rights reserved. Email CA about this topic