Previous Topic: Configure the Partnership EntitiesNext Topic: Set Up Single Sign-on


Create the IdP-to-SP Partnership

After creating the partnership entities, follow the partnership wizard to configure the IdP ->SP partnership. The first is to provide the name and other basic information for the partnership.

Follow these steps:

  1. Select the Federation tab.
  2. Click Create Partnership, SAML2 IdP -> SP.

    Selecting this option indicates that you are the local IdP.

    You come to the first step in the partnership wizard.

  3. Complete the fields with the following values:
    Partnership Name

    TestPartnership

    Local IDP ID

    idp1

    (selected from the pull-down list)

    Remote SP ID

    sp1

    (selected from the pull-down list)

    Base URL

    http://idp1.example.com:9090

    This value should be provided by default.

    Skew Time (Seconds)

    Accept the default

  4. Move the ODBC directory (FedSQL) from the Available Directories box to the Selected Directories box.
  5. Click Next to go to the Federation Users step.

Specify Federation Users for Assertion Generation

In the Federation Users dialog, select the users for which the IdP generates assertions.

Follow these steps:

  1. Accept the defaults.
  2. Click Next to continue.

By accepting the defaults, you indicate that CA SiteMinder® can generate assertions for all users in the user directory.

Add a Name ID to the Assertion

The Assertion Configuration step lets you specify the format and value of the NameID and the attributes that identify a user. These attributes are included in the assertion.

Note: NameID is always included in the assertion.

In this configuration, specify only the Name ID. Do not add any other attributes.

Follow these steps:

  1. From the Assertion Configuration step, enter values for the following fields:
    Name ID Format

    Unspecified

    Name ID Type

    Static

    Value

    GeorgeC

  2. Click Next to move on and set up single sign-on (SSO).