The federation partnership definition specifies which federation role is local, and which federation role is remote.
Follow these steps:
Note: Click Help for a description of fields, controls, and their respective requirements.
The Create Federation Partnership dialog displays the first step in partnership configuration.
In the Configure Partnership step of the wizard, identify the partnership by naming the partnership and specifying the local and remote entities.
Note: Click Help for a description of fields, controls, and their respective requirements.
Follow these steps:
Note: This step can be deferred if you are planning to create the remote entity by importing metadata later.
The skew time is the difference between the system time on the local system and the system time on the remote system. Usually, the inaccuracy of system clocks causes this condition. Determine the skew time number by subtracting the number of seconds from the current time.
The system uses the skew time and the SSO validity duration to determine how long an assertion is valid.
If you configure only one user directory, that directory is automatically placed in the Selected Directories list.
Important! To use an ODBC database as a user directory, define an SQL Query scheme and valid SQL queries. These steps are necessary before you can select it as a user directory.
Note: If you are editing a partnership, you can click Get Updates next to this field to update the entity information. The latest information from the entity configuration is propagated to the partnership. However, if you edit the entity information directly from the partnership, the changes do not get propagated back to the individual entity configuration.
You can click Get Updates next to the local and remote entity fields to update information about the entity. When you select Get Updates, the system asks to pull in the latest information from the entity.
After confirmation, the partnership you are editing is refreshed with the latest entity information. Changes are saved when you complete the partnership wizard. If you do not confirm the update, the partnership configuration remains the same.
The Entity Name identifies an entity object for in the policy store. The Entity Name must be the unique identifier because the product uses this value internally to distinguish an entity. This value is not used externally and the remote partner is not aware of this value.
If the Entity ID represents a remote partner, the value must be unique. If the Entity ID represents a local partner, it can be reused on the same system.
Note: The Entity Name can be the same value as the Entity ID, but do not share the value with any other entity.
An entity is a key component of a federation partnership. Changing an entity alters the partnership significantly; therefore, the Administrative UI does not let you replace an entity after it is in a partnership. To replace an entity, create a partnership.
To provide some flexibility within partnership configuration, you can change an entity ID because it does not identify the entity uniquely. Changing the entity ID at the partnership level does not link the partnership to another entity. The original entity in the partnership does not change. Modifications to an entity are a one-way propagation from the entity to the partnership. A change to the entity ID at the partnership does not get propagated back to the original entity.
Regard entity configurations as templates. Partnerships are created based on the entity templates so changing the partnership does not change the original entity template.
Review the partnership configuration before saving it.
Follow these steps:
The partnership configuration is complete.
|
Copyright © 2013 CA.
All rights reserved.
|
|