Previous Topic: Use a Search Specification to Locate a UserNext Topic: Configure the Backchannel for HTTP-Artifact SSO


Configure Single Sign-on at the SP

To establish single sign-on between the Identity Provider and the Service Provider, specify the SSO bindings supported by the Service Provider.

The SSO tab configures single sign-on using the artifact or POST binding. This tab also enforces single use assertion policy for POST binding to prevent the replaying of a valid assertion.

Part of the single sign-on configuration is defining the Redirect Mode setting. The Redirect Mode specifies how Federation Security Services sends assertion attributes, if available, to the target application. You can send assertion attributes as HTTP Headers or HTTP cookies.

The HTTP headers and HTTP cookies have size restrictions that assertion attributes cannot exceed. The size restrictions are as follows:

To configure single sign-on

  1. From the Authentication Scheme Properties dialog, click Additional Configuration.

    The SAML 2.0 Auth Scheme Properties dialog opens.

  2. Select the SSO tab.
  3. Complete entries for the fields on the SSO tab.

    The following are required fields:

  4. Specify a target resource for single sign-on to work. The target specifies the requested resource at the destination Service Provider site and it is required.
  5. In the Bindings section, you can select both HTTP-Artifact and HTTP-Post.

    If HTTP-POST is selected and artifact is not selected, only the POST binding is accepted from the Identity Provider. If no binding is specified, the default is HTTP-artifact.

    If you select HTTP-Artifact binding,

  6. The following are other optional features you can select:

More Information:

Configure the Authentication Scheme that Protects the Artifact Service