Previous Topic: Configure POST Single Sign-on at the IdP

Next Topic: Federation Web Services Access

Protect the Authentication URL (SAML 2.0)

You must protect the Authentication URL with a SiteMinder policy. Protecting the Authentication URL ensures that a user requesting a protected federated resource is presented with an authentication challenge if they do not have a SiteMinder session at the IdP.

To protect the Authentication URL at the Identity Provider

  1. From the Domains tab, create a policy domain called Authentication URL Protection Domain.
  2. Add the IdP LDAP user directory in the User Directories tab.
  3. From the Authentication URL Protection domain, create a persistent realm with the following field entries:

    Accept the defaults for the other settings.

  4. From the IDP Authentication URL Protection Realm, create a rule under the realm with the following field entries:

    Accept the defaults for the other settings.

  5. From the Authentication URL Protection domain, create a policy with the following entries:

    You now have a policy that protects the Authentication URL at the Identity Provider.

More Information:

Protect the Authentication URL to Create a SiteMinder Session (SAML 1.x)


Copyright © 2010 CA. All rights reserved. Email CA about this topic