The authentication schemes that correspond to the advanced authentication flows are preconfigured in the CSP console. These authentication schemes are:
You establish a one-to-one correspondence between an authentication method that is configured in the User Console and an authentication scheme in the CSP console. The authentication method and authentication scheme work together to protect access to the specified application.
The authentication scheme protects the authentication URL that is specified for a given authentication method. To apply the authentication scheme, assign the authentication scheme to a realm and then include the realm in a policy.
Follow these steps:
A realm groups resources that have similar security requirements and share a common authentication scheme. In the tenant domain, create a realm for each authentication scheme that the tenant administrator wants to use.
Note: The following procedure assumes that you are creating an object. You can also copy the properties of an existing object to create an object.
Follow these steps:
The Realms screen opens.
Note: The tenant domain name is in the tenant-tagDomain format.
Specify a name that indicates that the realm is for an authentication URL.
For environments created in CA CloudMinder 1.51 or later:
/chs/redirect/tenant_tag/arcototp
For environments created before CA CloudMinder 1.51:
/affwebservices/<tenant-name>/arcototp.jsp
For environments created in CA CloudMinder 1.51 or later:
/chs/redirect/tenant_tag/arcototprisk
For environments created before CA CloudMinder 1.51:
/affwebservices/<tenant-name>/arcototprisk.jsp
For environments created in CA CloudMinder 1.51 or later:
/chs/redirect/tenant_tag/arcotid
For environments created before CA CloudMinder 1.51:
/affwebservices/<tenant-name>/arcotid.jsp
For environments created in CA CloudMinder 1.51 or later:
/chs/redirect/tenant_tag/arcotidrisk
For environments created before CA CloudMinder 1.51:
/affwebservices/<tenant-name>/arcotidrisk.jsp
tenant_tag is a unique identifier for a tenant. You specify the tag when deploying a tenant environment in the CSP console. To view a list of tags, select the Tenants tab.
Protected
Select the authentication scheme that corresponds to the resource filter.
The Create Rule screen opens.
The rule is created.
Note: Click Help for information about these properties.
The realm is configured.
Rules indicate which resources are part of a policy and whether to allow or deny access to the resources when the rule fires.
Note: Add at least one rule or rule group to a policy.
Follow these steps:
The Domains screen opens.
The Available Rules pane opens.
The rule is added to the tenant policy.
|
Copyright © 2015 CA Technologies.
All rights reserved.
|
|