Previous Topic: CA Arcot

Next Topic: Active Directory


Protecting ArcotID Tasks When CA SiteMinder Protects CA IdentityMinder

If CA SiteMinder protects CA IdentityMinder using an Arcot authentication scheme, the following tasks do not work in CA IdentityMinder:

The ArcotID credential enables two-factor authentication for CA SiteMinder applications that an Arcot authentication scheme protects.

CA SiteMinder supports only one authentication scheme for a protected resource. All CA IdentityMinder protected tasks have the same URL, which is protected by one CA SiteMinder authentication scheme.

Do not use Arcot authentication to protect the URL for accessing CA IdentityMinder protected tasks.

When Arcot authentication protects the CA IdentityMinder protected tasks URL, users must provide an ArcotID to access tasks such as Create/Reset My ArcotID or Download My ArcotID. Users who access these tasks do not have an ArcotID yet, so they cannot provide it to access the tasks.

When CA SiteMinder protects CA IdentityMinder tasks, use an authentication scheme other than Arcot, such as Active Directory or LDAP, to prevent this issue.

Note: Since Create/Reset My ArcotID or Download My ArcotID are sensitive tasks, CA Technologies strongly recommends configuring these tasks as protected tasks. If you configure these tasks as public tasks, users can access them without providing credentials.

For more information about public tasks, see Self-Service Tasks in the User Console Design Guide.