Federation Manager Guide › Federation Manager Introduction › Federation in Your Enterprise › Federation Manager Partnership Model
Federation Manager Partnership Model
Federation Manager's partnership model can establish a federation between Financepro and BankLtd to ease the experience of moving between each company's site and to ensure they appear as one company.
The Federation Manager UI focuses on partnership creation and identifying each side of the partnership to accomplish single sign-on.
These steps include:
- Configuring a PartnershipNames the partnership and identifies the two entities that make up the partnership.
- Establishing the Federation Users/User IdentificationSpecifies the users for which the asserting party generates assertions and the relying party authenticates.
- NameID and AttributesDetermines how a federated identity is established and lets you add attributes to further identify and customize the content of the assertion.
Using NameID and attributes, you can ensure the appropriate information is available to the application at the relying party. This is where account linking and identity mapping would be configured.
- SSODefines Single Sign-on (Artifact or POST binding), including the location of the service consuming assertions at the relying party. For SAML 2.0, additional features, such as single logout (SLO), Enhanced Client or Proxy (ECP) profile, and Identity Provider Discovery profile can be configured.
- Signature and EncryptionDefines the signature and encryption options for secure exchange of assertions, authentication requests, and for SAML 2.0 single logout requests and responses.
- Application IntegrationEnables you to configure redirection to the target application, lets you set up provisioning of user records, and define relying-party side attribute mapping. You can also set up redirects for failed user authentication.