Previous Topic: WS-Federation Assertion GeneratorNext Topic: Customizing SAML 2.0 Assertion Responses


SAML and WS-Federation Authentication Schemes

SiteMinder supports the following authentication schemes:

Each authentication scheme enables a SiteMinder site to consume SAML assertions. Upon receiving an assertion, the authentication scheme validates the SAML assertion, maps assertion data to a local user, and establishes a SiteMinder session at the site consuming the assertion.

One of the critical features of the SAML authentication schemes is to map remote users at an asserting party to local users at the relying party. The mapping is defined as part of the authentication scheme configuration. User mapping information enables the authentication scheme to locate the correct user record for authentication.

The SAML and WS-Federation authentication schemes are installed by the Policy Server. After installation, the administrator can use the FSS Administrative UI to define and configure these schemes and use them to protect specific resources.