Previous Topic: Configure a CRYPTOCard RB-1 Authentication Scheme

Next Topic: HTML Forms Scheme Prerequisites

HTML Forms Authentication Schemes

HTML Forms authentication schemes provide a method for authentication based on credentials gathered in a custom HTML form. This flexible means of credential collection allows you to:

Multiple Forms-based Authentication Schemes can be configured in a Policy Server installation. Each scheme consists of the following components:

The previous diagram describes the process for HTML Forms authentication.

  1. A user requests a resource contained in a realm protected by HTML Forms authentication.
  2. The Web Agent contacts the Policy Server and determines that the user's request must be redirected to the credential collector.
  3. The Web Agent redirects the request to the URL of the credential collectorfile.
  4. The credential collector displays the form described in the .fcc file in the user's browser.
  5. The user fills out the custom form and Posts (submits) the form. The credential collector processes the credentials.
  6. The credential collector (FCC) logs the user into the Policy Server. The Policy Server returns user session data to the credential collector.
  7. If the user is authenticated, the credential collector creates a session cookie, passes the session cookie to the browser and redirects the user to the resource that he or she originally requested.
  8. The user uses the session cookie to authenticate. Then, the Web Agent handles user authorization.

More information:

SiteMinder FCC Files


Copyright © 2010 CA. All rights reserved. Email CA about this topic