Previous Topic: Intended AudienceNext Topic: CA Business Intelligence


Sample SiteMinder Installation

Installing SiteMinder requires you to install and configure several components. The following diagram shows:

Policy Server

(Required) A SiteMinder Policy Server (Policy Server) acts as the Policy Decision Point (PDP). The purpose of the Policy Server is to evaluate and enforce access control policies, which it communicates to a SiteMinder Agent. A Policy Server provides the following:

The Policy Server interacts with all other major components to perform these tasks.

Policy Store

(Required) The SiteMinder policy store (policy store) is an entitlement store that resides in an LDAP directory server or ODBC database. The purpose of this component is to store all policy-related objects, including the:

The Policy Server uses this information, collectively known as an Enterprise Policy Management (EPM) application or SiteMinder policy, to determine if a resource is protected and if an authenticated user is authorized to access the requested resources.

Key Store

(Required) The purpose of this component is to store the encryption keys that the Policy Servers and the agents use to encrypt sensitive data, which include:

You can collocate the key store with the policy store or you can store encryption keys in a separate directory or database. The need to deploy a separate key store depends on:

Note: If you use the Policy Server Configuration wizard to configure a policy store, the key store is automatically collocated with the policy store.

More information:

Documentation Roadmap

Certificate Data Store

(Optional) The SiteMinder certificate data store (CDS) makes the following components and functions available to a SiteMinder environment:

Note: SiteMinder federation features use the certificate data store. The user certificates that the X.509 certificate authentication scheme uses for authentication are not stored in the certificate data store. These user certificates are stored in an LDAP/AD user directory or ODBC store.

By default, the certificate data store is automatically configured and colocated with the policy store. As a result:

SiteMinder Administrative UI

(Required) The SiteMinder Administrative UI (Administrative UI) is a web–based administration console that is installed independent of the Policy Server. The Administrative UI is intended for managing all tasks that are related to access control, reporting, and policy analysis.