After establishing the user directory connection, you should identify the local and remote sides of the partnership. In the Federation Manager UI, each partner is referred to as an entity.
The following procedures tell you what values to provide for the local and remote entities. However, in a real network configuration, it may be common that each side creates a local entity, exports the local entity to a metadata file, then exchanges the files so that each side can define the remote entity.
To create the Local IdP
The View Federation Entities window opens.
The Create Entity dialog displays.
Local
SAML2 IDP
idp1
This value identifies the entity to the partner.
idp1
This value identifies the entity object internally in the Federation Manager database. The partner is not aware of this value.
http://idp1.example.com:9090
Leave the other settings as they are.
Note: The Entity Name can be the same value as the Entity ID, but the value must then not be shared with any other entity at the site.
You return to the View Federation Entities window. Configure the remote partner.
To create the Remote SP Entity
The Create Entity dialog displays.
Remote
SAML2 SP
sp1
This value identifies the entity to the partner.
sp1
This value identifies the entity object internally in the Federation Manager database. The partner is not aware of this value.
0
HTTP-Post
http://sp1.demo.com:9091/affwebservices/public/
saml2assertionconsumer
Select the checkbox in this column for the entry row.
Leave the other settings as they are.
The remote SP entity is configured.
After the local and remote entity are configured, you can now create a partnership.
| Copyright © 2010 CA. All rights reserved. | Email CA about this topic |