Federation Security Services Guide › Overview of a SiteMinder Federation Partnership Setup › Set Up Producing Authority Components › Set up Affiliate Domains and Add Sites to these Domains
Set up Affiliate Domains and Add Sites to these Domains
Before you set up Federation Web Services, you establish affiliate domains and add the sites that will consume assertions to the affiliate domains. This identifies the partners to the site producing the assertions.
At the producing authority:
- Access the FSS Administrative UI.
- Create an affiliate domain.
- Add a user store for users that the producing authority (producer, IdP, AP) will generate assertions.
- Add an object for each consuming authority (consumer, SP, RP) to the affiliate domain.
There should be a one-to-one correspondence between a consuming authority and each object added to the domain.
- After adding sites to an affiliate domain, ensure that you protect the AuthenticationURL, which ensures that a user has a session at the producing authority prior to process a request for a federated resource.
To do this:
- Create a policy domain.
- Protect the policy domain with the Web Agent that is protecting the server with the Web Agent Option Pack.
- To this policy domain, add a realm, rule, and policy that protects the Authentication URL.