This section contains the following topics:
Configure a SiteMinder Agent Security Interceptor Authentication Realm
(Optional) Configure the Agent to Return Group Membership to JBoss Using Responses
Example: Configure the SiteMinder Agent Web Interceptor to return groups using responses
Configure Security Policies for the Proxy Server Web Agent
Configure an authentication realm on the Policy Server to allow the SiteMinder Agent Security Interceptor to validate users credentials using information obtained from CA SiteMinder® session cookies. Use the Administrative UI to create the SiteMinder Agent Security Interceptor authentication realm.
Follow these steps:
Note: You can click Help for a description of fields, controls, and their respective requirements.
Note: You do not need to configure any rules for the validation realm.
The Create Realm Task is submitted for processing.
The Create Domain Task is submitted for processing.
The SiteMinder Agent Web Interceptor can be configured to return physical or virtual group membership information to JBoss using SiteMinder HTTP header responses from the Policy Server during user authentication.
When the SiteMinder Agent Web Interceptor receives responses containing the _SM_JBOSS_GROUP=group name syntax, the SiteMinder Agent Web Interceptor converts the group_name value to a J2EE principal and adds this principal to the subject after successful authentication.
Specifies a response attribute value from the Policy Server that could be a physical group name from the user store or a virtual group.
The SiteMinder Agent adds the same amount of group principals as responses received from the Policy Server.
Note: The SiteMinder Agent Web Interceptor can only process _SM_JBOSS_GROUP response attributes to return group membership information to JBoss. It cannot process other response attributes added to HTTP header variables to pass information to a web application.
To configure Groups as responses for the SiteMinder Agent
Note: The SiteMinder Administrative UI shows an additional underscore before "_SM_JBOSS_GROUP" when it displays the variable name, so that it appears as "HTTP__SM_JBOSS_GROUP". This is not an error and can be ignored.
The following example shows one method of configuring the SiteMinder Agent Web Interceptor to return groups using responses:
Attribute kind: Static HTTP Header
Variable name: _SM_JBOSS_GROUP
Variable value: Administrators
Attribute kind: Static HTTP Header
Variable name: _SM_JBOSS_GROUP
Variable value: Deployers
Attribute kind: Static HTTP Header
Variable name: _SM_JBOSS_GROUP
Variable value: Monitors
Attribute kind: Static HTTP Header
Variable name: _SM_JBOSS_GROUP
Variable value: Operators
To configure the SiteMinder Agent for JBoss to protect web applications by perimeter authentication, create policies that specify how the Web Agent on the proxy server controls access to the URL that represents the proxied JBoss web application resources.
Copyright © 2014 CA.
All rights reserved.
|
|