To add sp.demo to the affiliate domain, specify values on the Users tab, the General tab, and the SSO tab before you can save a Service Provider object.
To add sp.demo to the Federation Sample Partners domain
sp.demo
Service Provider
http://www.idp.demo/siteminderagent/redirectjsp/redirect.jsp
This redirect.jsp is included with the Web Agent Option Pack that is installed at the Identity Provider site. In this deployment, that server is www.idp.demo. If the user does not have a SiteMinder session, the SSO service at the IdP redirects the user to the authentication URL for log in.
After successful authentication, the redirect.jsp application redirects the user back to the SSO service for assertion generation. A SiteMinder policy must protect this URL.
Verify that this option is selected. By default, this option is selected.
You must protect the Authentication URL with a SiteMinder policy. Protecting the Authentication URL ensures that a user requesting a protected federated resource is presented with an authentication challenge if they do not have a SiteMinder session at the IdP.
To protect the Authentication URL at the Identity Provider
Authentication URL Protection Realm
Using the lookup button, select FSS web agent
This is the Web Agent protecting the server with the Web Agent Option Pack.
/siteminderagent/redirectjsp/redirect.jsp
Accept the defaults for the other settings.
Select Persistent Session
Authentication URL Protection Rule
Authentication URL Protection Realm
*
Get
Accept the defaults for the other settings.
Authentication URL Protection Policy
Add user1 from the IdP LDAP user directory
add Authentication URL Protection Rule
You now have a policy that protects the Authentication URL at the Identity Provider.
Copyright © 2012 CA.
All rights reserved.
|
|