At the Service Provider, install the Policy Server.
Set up the Policy Server.
To install the Policy Server
For instructions, see the SiteMinder Policy Server Installation Guide.
In this deployment, an IIS Web Server is the server on which the Policy Server is installed. Your network can use a different supported web server.
In this deployment, a Sun Java LDAP directory is serving as the policy store. The installation configures and initializes this policy store for you.
Important! If you initialize a new policy store, the Policy Server installer automatically imports the affiliate objects contained in the ampolicy.smdif file. These objects are necessary for federation. If you use an existing policy store that you do not initialize, import the affiliate objects manually. To verify that the import is successful, log in to the FSS Administrative UI and click on Domains in the System tab. If the import is successful, you can see the FederationWebServices domain object.
Point the Policy Server to the LDAP Policy Store.
Establish the connection between the Policy Server and the LDAP policy store.
Follow these steps:
Complete the following fields:
Policy Store
LDAP
sp.demo:389
o=sp.demo
cn=Directory Manager
federation
federation
At the SP, configure a user store and add user records for users that require assertions. When the assertion is presented during authentication, the Service Provider looks in the user store for the user record.
In this deployment, the Sun ONE LDAP user directory is the user store. Use the Sun ONE Server Console to add users to the directory.
To configure the user store
userpassword: customer
mail: user1@sp.demo
userpassword: customer
mail: user2@sp.demo
Important! The email address must be the same in the Identity Provider user store for the same users.
At the SP Policy Server, configure the SiteMinder Profiler to log federation components to the trace log, smtracedefault.log and examine trace messages.
To enable logging
To configure trace logging at the Policy Server, using the Policy Server Management Console.
Copyright © 2012 CA.
All rights reserved.
|
|