The following table lists all supported authentication schemes and their credential requirements:
|
Credential Requirements |
||||
---|---|---|---|---|---|
Authentication Schemes |
Directory User Name |
Directory Password |
Code from Token |
X.509 Certificate |
User Profile Attributes |
Anonymous |
|
|
|
|
|
Basic |
yes |
yes |
|
|
|
Basic over SSL |
yes |
yes |
|
|
|
Custom |
optional |
optional |
optional |
optional |
optional |
HTML Forms (over SSL optional) |
custom credentials |
custom credentials |
|
|
optional |
Impersonation |
yes |
|
|
|
optional |
MS Passport |
yes |
yes |
|
|
yes |
NTLM or Windows |
yes* |
yes* |
|
|
|
RADIUS CHAP/PAP |
yes |
yes |
|
|
|
RADIUS Server |
yes |
yes |
|
|
|
SafeWord Server |
yes |
yes |
|
|
|
SafeWord and Forms |
yes |
yes |
|
|
optional |
SecurID |
yes |
|
yes |
|
|
SecurID and Forms |
yes |
|
yes |
|
optional |
TeleID |
yes |
|
yes |
|
|
X.509 Client Certificate |
|
|
|
yes |
|
X.509 Client Certificate and Basic (uses SSL) |
yes |
yes |
|
yes |
|
X.509 Client Certificate or Basic (over SSL optional) |
yes for Basic |
yes for Basic |
|
yes for Certificate |
|
X.509 Client Certificate and HTML Forms |
custom credentials |
custom credentials |
|
yes |
optional |
X.509 Client Certificate or HTML Forms |
custom credentials for HTML Forms |
custom credentials for HTML Forms
|
|
yes for Certificate |
optional for HTML Forms |
*For NTLM or Windows, when trying to access a resource, SiteMinder does not prompt the user to enter a username and password. This scheme relies on a properly-configured IIS Web server to acquire and verify a user’s credentials. The Policy Server bases authorization decisions on the user’s identity as asserted by the IIS server.
Set up an authentication scheme in the Administrative UI. Configure the components in the following order:
For a Web Agent to support any SSL-based Authentication Scheme, configure a web server for SSL.
After you configure your web servers to support authentication schemes, configure the Policy Server to support the schemes.
You can configure multiple instances of most authentication schemes in the Administrative UI. For example, you can create multiple HTML forms-based schemes to process login, forgotten password requests, and logout. If you create multiple instances of a scheme type, set protection levels to reflect your security requirements.
Copyright © 2012 CA Technologies.
All rights reserved.
|
|