The SOA Security Manager policies application protects the Federation Web Services (FWS).
When you install the [set to your product name], SOA Security Manager creates the necessary policies and the related policy objects automatically. Each service has one policy that makes up the Federation Web Services application.
The following table lists the objects and policies that protect FWS.
|
Object Type |
Object Name |
|---|---|
|
Domain |
FederationWebServicesDomain |
|
Realm |
FederationWebServicesRealm public |
|
Agent Group |
FederationWebServicesAgentGroup |
|
Rule |
FederationWSAssertionRetrievalServiceRule FederationWSNotificationServiceRule FederationWSSessionServiceRule SAML2FWSArtifactResolutionRule |
|
Policy |
FederationWSAssertionRetrievalServicePolicy FederationWSNotificationServicePolicy SAML2FWSArtifactResolutionServicePolicy |
|
User Context Variable |
AllowNotification |
|
User Context Variable |
AllowSessionSync |
|
User Directory |
FederationWSCustomUserStore SAML2FederationCustomUserStore |
You must enforce protection of the Federation Web Services policies
To enforce policies to protect the Federation Web Services application
For ServletExec, this Agent is on the web server where the Web Agent Option Pack is installed. For any application server, such as WebLogic or JBOSS, this Web Agent is installed where the application server proxy is installed. The Web Agent Option Pack can be on a different system.
Note: Establish affiliate domains and add affiliates to the domains before you give permission to the affiliates.
All other aspects of configuring the policies, such as the Basic authentication scheme, realms and rules are set up automatically.
| Copyright © 2011 CA. All rights reserved. | Email CA Technologies about this topic |