Previous Topic: Configure Assertion OptionsNext Topic: Assertion Validity for Single Sign-on


Single Sign-on Configuration (Asserting Party)

Configure single sign-on at the asserting party to specify how the asserting party delivers an assertion to a relying party.

Follow these steps:

  1. Begin at the appropriate step in the partnership wizard.
    SAML 1.1 and WS-FED

    Single Sign-On

    SAML 2.0

    SSO and SLO

    Any values that are defined during the creation or import of the remote relying party are filled in.

    Note: Click Help for a description of fields, controls, and their respective requirements.

  2. In the Authentication section, configure the following fields so CA CloudMinder can act as the IdP
    Authentication Mode

    Delegated

    Delegated Authentication Type

    Cloud

    Delegated Authentication URL

    Enter the URL of the system authenticating the user requesting a resource. Use the following syntax for the delegated URL:

    http://cloud_system:port/chs/login/tenant_name/application_name

    The cloud_system is the system where the user console is installed.

    Example URL:

    http://cmserver.fowardinc.com:832/chs/login/tenant1/confidential_app

    Configure AuthnContext

    Use Predefined Authentication Class

    Authentication Class field

    Supply a static URI for SAML 1.1, SAML 2.0, and WS-FED.

    Additionally, for SAML 2.0 only, the system can automatically detect an authentication class. The URI is placed in the AuthnContextClassRef element in the assertion to describe how a user is authenticated.

  3. Complete the fields in the SSO section to determine how single sign-on operates. These settings let you control the following features:

    For SAML 2.0, you can configure these features:

    Note: Click Help for a description of fields, controls, and their respective requirements.

  4. Specify the URL for the Remote Assertion Consumer Service. This service is the service at the relying party that processes received assertions.

    Your partner needs to supply this URL to you.

  5. If you selected HTTP-Artifact, configure the back channel settings.