Previous Topic: Configuration ConsiderationsNext Topic: Multiple Data Centers


Security Zones

Security Zones are groups of resources in a single cookie domain that a CA SiteMinder® Web Agent protects. Users authenticate once, and can then access other resources in the zones (for which they are authorized) without being rechallenged.

Without Security Zones, users could possibly be challenged each time they access a protected resource in the same cookie domain; even if they have previously been authenticated by CA SiteMinder® for another resource in the cookie domain. The following illustration shows an example:

Graphic showing an example scenario in which users must authenticate for each time they access a resource, even if they have used it previously in the same session, if the SSO security zones are unavailable

Consider implementing Security Zones in the following situations:

The following illustration shows how Security Zones can be used so that only a single log in allows a user access to resources in Security Zones 1 and 3, but prevents access to unauthorized resources in Security Zone 2:

Graphic showing an example of SSO Security Zones which shows an Authenticated User of a Domain Has Access to Zones 1 and 3 but not Zone 2

Note: For more information, see the Web Agent Configuration Guide.