Previous Topic: Query String Encryption of Redirect URLs

Next Topic: Query String Encryption of Redirect URLs and FCC-based Password Services

Query String Encryption of Redirect URLs and Credential Collectors

When you encrypt the query strings of redirect URLs use credential collectors, the credential collectors provide the keys used to encrypt the query data.

For forms authentication schemes, the query string directive, smquerydata, is part of the FCC template. The Web Agent serving the FCC uses this directive to send the encrypted query data to the target Web Agent when the FCC is posted.

The following directive is used:

<INPUT type='hidden' name='smquerydata' value='$$smquerydata$$'>

Note: If you are using custom FCCs, you must add the smquerydata directive along with other FCC directives, such as TARGET to the custom FCC.

SiteMinder r12.0 SP2 Web Agents with the SecureUrls parameter enabled can operate only with credential collectors served from other Web Agents that support this functionality, which was introduced at 5.x QMR 7.


Copyright © 2006 CA. All rights reserved. Email CA about this topic