Federation Security Services Guide › Authorize Users with Attributes from an Assertion Query › Set up a SAML Requestor to Generate Attribute Queries › Create a Federation Attribute Variable
Create a Federation Attribute Variable
To use a federation attribute variable in a policy expression, first create the attribute variable.
To define a federation attribute variable
- Log on to the FSS Administrative UI.
- From the list of Domains, expand the policy domain where the variable is added.
- Expand the Variables list by clicking the plus (+) symbol.
- Select Federation Attribute Variable then select Edit, Create Variable
The Federation Attribute Variable Properties dialog opens.
- Complete all the fields in the dialog.
- Click OK to save the variable.
- Add this variable to an expression used by a policy that protects a federated resource.
Note: A policy expression can use multiple Federation attribute variables; each variable is tied to a SAML 2.0 authentication scheme. Therefore, a single expression can result in many attribute requests sent to many Attribute Authorities.
Copyright © 2012 CA.
All rights reserved.
|
|