Previous Topic: Configure Policy Objects for the SiteMinder Agent Security Interceptor

Next Topic: (Optional) Configure the Agent to Return Group Membership to JBoss Using Responses

Configure a SiteMinder Agent Security Interceptor Authentication Realm

Configure a realm on the Policy Server to allow the SiteMinder Agent Security Interceptor to validate users' credentials using information obtained from SiteMinder session cookies. You use the SiteMinder Administrative UI to create the SiteMinder Agent Security Interceptor authentication realm.

For more information about the SiteMinder Administrative UI and its use to create domains and realms, see the CA SiteMinder Policy Configuration Guide.

To configure a SiteMinder authentication realm for JBoss web application resources

  1. Click Policies, Domains.
  2. Click Domain, Create Domain.
  3. The Create Domain pane opens.

    Note: You can click Help for a description of fields, controls, and their respective requirements.

  4. Type the name and a description of the Domain in the fields on the General group box.
  5. Add one or more user directories that contain the users who can access the protected resources.
  6. Create the validation realm:
    1. Click the Realms tab on the Domain pane, New Realm, OK.
    2. The Create Realm pane opens.
    3. Enter the following information:
      • Name: A unique name for the realm—for example, SiteMinder Agent Security Interceptor Validation Realm
      • Description: An optional description for the validation realm
      • Agent: The name of the SiteMinder Agent identity that you created for the SiteMinder Agent for JBoss.
      • Resource Filter: /smauthenticationrealm
      • Authentication Scheme: Basic

      Note: You do not need to configure any rules for the validation realm.

    4. Specify session properties in the Session group box:
      • Disable all session time-outs
      • Ensure the No Persistent Session option is selected
    5. Click Finish.

      The Create Realm Task is submitted for processing.

  7. Click Submit.

    The Create Domain Task is submitted for processing.