Previous Topic: Protect Federation Web Services (Consuming-side)

Next Topic: Create Links to Initiate Single Sign-on (optional)

Set-up the smkeydatabase for Artifact Single Sign-on (optional)

The smkeydatabase is a local flat-file key database that stores keys and certificates needed for PKI specific operations such as encryption, decryption, signing, verification and client authentication.

If you are implementing artifact single sign-on, smkeydatabase at the producing authority holds the certificate authority's certificate for establishing an SSL connection from the consuming authority to the web server at a producing authority. This secures the back channel that the assertion is sent across for artifact single sign-on.

A set of common root CAs are shipped in the default smkeydatabase. To use root CAs for web servers that are not in smkeydatabase, import these root CAs into the file.

To modify smkeydatabase, use the smkeytool utility.

More Information:

Manage the Key Database for Signing and Encryption


Copyright © 2010 CA. All rights reserved. Email CA about this topic