Previous Topic: Indexed Endpoints Flow Diagram

Next Topic: Enforce the Authentication Scheme Protection Level for SSO

Define Indexed Endpoints for Different Single Sign-on Bindings

You can configure indexed endpoints for federated communication. An indexed endpoint is the site where assertions are consumed. In the context of SOA Security Manager, this endpoint is the Service Provider where the Assertion Consumer Service resides.

Each endpoint you configure is assigned a unique index value, instead of a single, explicit reference to an Assertion Consumer Service URL. The assigned index is added to the assertion request that the Service Provider sends to the Identity Provider.

You can configure indexed endpoints for a SOA Security Manager Service Provider that has a federated relationship with a third-party Identity Provider that supports indexed endpoints. You can also configure different protocol bindings (artifact, POST) for the Assertion Consumer Service by assigning more than one endpoint to the service.

Note: If your network contains different SOA Security Manager versions, for example, the Service Provider is r6.0 SP 5 and the Identity Provider is r6.0 SP 6, you cannot configure indexed endpoints. Configure only one Assertion Consumer Service for both HTTP bindings.

The following figure shows a network that benefits from indexed endpoints.

SM--Overview for Indexed Endpoints