For the realm containing the protected target resource, you need to create a rule that is triggered during the authorization process to retrieve the SAML attributes from the session store.
The rule is based on an authorization event (onAccessAccept) because the user has already been authenticated by the FWS application, therefore the Web Agent cannot re-authenticate the user and pass on the HTTP headers. So, the retrieval of the attributes must happen during the authorization stage.
To create an OnAccessAccept Rule for the realm
The Rule Properties dialog opens.
The authorization rule is now defined for the realm with the protected resource.
Copyright © 2010 CA. All rights reserved. | Email CA about this topic |