Create the policy at the asserting party to protect the service from which the asserting party retrieves the assertion.
Follow these steps:
In the user record, enter the same value that is specified in the Name field of the affiliate general settings in the Administrative UI. For example, if Company A is the value of the Name field for the affiliate, the user directory entry is:
uid=CompanyA, ou=Development,o=CA
The Policy Server maps the subject DN value of the affiliate client certificate to this directory entry.
Map the Attribute Name to the user directory entry for the affiliate. The attribute represents the subject DN entry in the certificate for the affiliate. For example, you select CN as the Attribute Name, and this value represents the affiliate named cn=CompanyA,ou=Development,o=partner.
Navigate to Infrastructure, Directory, Certificate Mappings for the mapping settings.
any_name
Example: cert assertion retrieval
FederationWebServicesAgentGroup
/affwebservices/certassertionretriever (SAML 1.x)
/affwebservices/saml2certartifactresolution (SAML 2.0)
Client certificate authentication scheme created in the previous step.
any_name
Example: cert assertion retrieval rule
*
GET, POST, PUT
The assertion retrieval service uses this HTTP header to verify that the affiliate is the site retrieving the assertion.
Create a response with the following values:
any_name
WebAgent-HTTP-Header-Variable
User Attribute
consumer_name
Enter the use directory attribute that contains the affiliate name value.
Example: uid=CompanyA.
Based on the following entries, the Web Agent returns a response named HTTP_CONSUMER_NAME.
any_name
Add the users from the user directory created in previously in this procedure.
rule_created_earlier_in_this_procedure
response_created_earlier_in_this_procedure
The policy to protect the artifact resolution service is complete.
At the relying party, the administrator has to enable client certificate authentication across the back channel that connects to the relevant assertion service:
SAML 1.x: Enable client certificate authentication for the Assertion Retrieval Service
SAML 2.0: Enable client certificate authentication for the Artifact Resolution Service
Copyright © 2012 CA.
All rights reserved.
|
|