Previous Topic: Specify the POST Binding Authentication at the SP

Next Topic: Protect the Target Resource at the SP

Configure the SAML 2.0 Authentication Scheme at the SP

To authenticate users at the Service Provider, configure the SAML 2.0 authentication scheme. The assertion from the IdP provides the credentials for authentication.

To configure the SAML 2.0 authentication scheme

  1. Log into the FSS Administrative UI.
  2. From the menu bar, select Edit, System Configuration, Create Authentication Scheme.

    The Authentication Scheme Properties dialog opens.

  3. Complete the following fields:

    Scheme Common Setup group box:

    Scheme Setup tab fields:

    Note: The SP ID and IdP ID values must match those at the IdP.

  4. In the D-Sign Info box, select the Disable Signature Processing checkbox.

    Important! Disabling signing is intended only for debugging the initial single sign-on configuration. In a production environment, signature processing is a mandatory security requirement so signature validation must be enabled and the key store must be set up to validate signatures.

  5. Click Additional Configuration.

    The SAML 2.0 Auth. Scheme Properties dialog opens.

  6. Leave the Authentication Scheme Properties dialog open and Configure User Disambiguation at the SP.

More information:

Set Up smkeydatabase at the SP for Signature Validation


Copyright © 2010 CA. All rights reserved. Email CA about this topic