Previous Topic: Configure CA SiteMinder® as a WS-Federation Resource PartnerNext Topic: Implement WS-Federation Signout


Configure WS-Federation Single Sign-on at the Resource Partner

You configure the WS-Federation single sign-on binding for authentication in the SSO section of the SAML Profiles page. You can also enforce single use assertion policy to prevent the replaying of a valid assertion in this section.

Part of the single sign-on configuration is defining the Redirect Mode setting. The Redirect Mode specifies how CA SiteMinder® sends assertion attributes, if available, to the target application. You can send assertion attributes as HTTP Headers or HTTP cookies.

The HTTP headers and HTTP cookies have size restrictions that assertion attributes cannot exceed. The size restrictions are as follows:

To configure WS-Federation single sign-on

  1. Navigate to the authentication scheme for the Resource Partner you are configuring.
  2. Select WS-Federation Configuration, SAML Profiles. Click Modify first if you are modifying an existing scheme.

    The SAML Profiles dialog opens.

  3. Complete the fields in the SSO section.

    Note: Click Help for descriptions of settings and controls, including their respective requirements and limits.

  4. Click Submit.