After establishing the user directory connection, you should identify the local and remote sides of the partnership. In the Federation Manager UI, each partner is referred to as an entity.
The following procedures tell you what values to provide for the local and remote entities. However, in a real network configuration it may be common that each side creates a local entity, exports the local entity to a metadata file, then exchanges the files so that each side can define the remote entity.
To create the local SP
The View Federation Entities window opens.
The Create Entity dialog displays.
Local
SAML2 SP
sp1
This value identifies the entity to the partner.
sp1
This value identifies the entity object internally in the Federation Manager database. The partner is not aware of this value.
http://sp1.demo.com:9091
Note: The entity ID and name must be the same as you specified for the remote SP entity at the Identity Provider.
You return to the View Federation Entities window. Configure the remote partner.
To create the remote IdP
The Create Entity dialog displays.
Remote
SAML2 IDP
idp1
This value identifies the entity to the partner.
idp1
This value identifies the entity object internally in the Federation Manager database. The partner is not aware of this value.
Note: The entity ID and name must be the same as on the Identity Provider side.
SSO Service URL Group Box
HTTP-Redirect
http://idp1.example.com:9090/affwebservices/public/saml2sso
After the local entity and remote entity are configured, you can create a partnership.
| Copyright © 2010 CA. All rights reserved. | Email CA about this topic |