Previous Topic: Use a Search Specification to Locate a WS-Federation UserNext Topic: Create a Custom WS-Federation Authentication Scheme (optional)


Configure WS-Federation Single Sign-on at the Resource Partner

The SSO tab configures the WS-Federation single sign-on binding for authentication. This tab also enforces single use assertion policy to prevent the replaying of a valid assertion.

Part of the single sign-on configuration is defining the Redirect Mode setting. The Redirect Mode specifies how Federation Security Services sends assertion attributes, if available, to the target application. You can send assertion attributes as HTTP Headers or HTTP cookies.

The HTTP headers and HTTP cookies have size restrictions that assertion attributes cannot exceed. The size restrictions are as follows:

To configure WS-Federation single sign-on

  1. Access the Authentication Scheme Properties dialog for the WS-Federation scheme.
  2. Click Additional Configuration.

    The WS-Federation Auth Scheme Properties dialog opens.

  3. Select the SSO tab.
  4. Select a value for the Redirect Mode field.
  5. Specify a target resource in the Target field for single sign-on to work. The target specifies the requested resource at the destination Resource Partner and it is required.
  6. Optionally, select the Enable Single Use Policy.
  7. Click OK to save your configuration.