Previous Topic: Create the IdP-to-SP PartnershipNext Topic: Configure the SP Partner


Set Up Single Sign-on

To establish single sign-on between partners, configure the SSO settings.

Follow these steps:

  1. Begin at the SSO and SLO step in the partnership wizard.
  2. Accept the default (Basic) for the Local Authentication Type and Authentication Class fields.
  3. Select HTTP-POST for the SSO Binding field.
  4. Assuming you created the remote SP entity already, the value for the Assertion Consumer URL is filled in.
  5. Click Next to move to the Signature and Encryption step.

Disable Signature Processing

For the purposes of this simple partnership, disable signature processing. However, in a production environment, the Identity Provider must sign assertions.

Follow these steps:

  1. From the Signature and Encryption step, select Disable Signature Processing.
  2. Click Next to move to the next step.

Confirm the IdP-to-SP Partnership Settings

You have completed the partnership definition for one side of the federation partnership. Verify the settings.

Follow these steps:

  1. In the Confirm dialog, review the settings for the partnership.
  2. To modify a setting, click Modify in any of the sections.
  3. Click Finish when you are satisfied with the configuration.

The IdP side of the partnership is complete. Define the SP side of the partnership on a different system than the IdP system.