Previous Topic: CA ArcotNext Topic: CA SSO Connector for Advanced Policy Server


Protecting ArcotID Tasks When CA SiteMinder Protects CA IdentityMinder or CA IdentityMinder

If CA SiteMinder protects CA IdentityMinder or CA IdentityMinder using a CA AuthMinder authentication scheme, the following tasks are disabled in CA IdentityMinder or CA IdentityMinder:

This is because CA SiteMinder defines one authentication scheme for a protected resource. All CA IdentityMinder protected tasks have the same URL, which is protected by one CA SiteMinder authentication scheme. This means that all CA IdentityMinder or CA IdentityMinder tasks are covered by the same authentication scheme.

When an ArcotID authentication protects the CA IdentityMinder or CA IdentityMinder URL, users have to provide an ArcotID to access tasks. Users who access the tasks listed above do not have an ArcotID yet, so they cannot provide it to access the tasks.

When CA SiteMinder protects CA IdentityMinder or CA IdentityMinder tasks, use an authentication scheme other than Arcot, such as Active Directory or LDAP, to prevent this issue.

Note: Since Create/Reset My ArcotID or Download My ArcotID are sensitive tasks, CA Technologies strongly recommends configuring these tasks as protected tasks. If you configure these tasks as public tasks, users can access them without providing credentials.

For more information about public tasks, see Self-Service Tasks in the User Console Design Guide.