Previous Topic: SAML 2.0 Artifact and POST Profiles

Next Topic: SAML Affiliate Agent

WS-Federation Passive Requestor Profile

For WS-Federation Passive Requestor profile, the Federation Web Services application uses the following services:

Security Token Consumer Service

A Resource Partner component that receives a security token and extracts the corresponding SAML assertion. The Security Token Consumer Service issues SOA Security Manager cookies to a user’s browser.

Single Sign-on Service

Enables processing for an Account Partner to process a wsignin WS-Federation message and gather the necessary Resource Partner configuration information to authenticate the user, redirect the user to the Web Agent to authenticate, and invokes the assertion generator to obtain an assertion that is passed back to the Resource Partner.

Signout Service

Implements processing of single logout functionality by way of a signout servlet. Signout can be initiated by an Account Partner or a Resource Partner.