Federation Security Services Guide › Configure SiteMinder as a Resource Partner › How To Protect a Target Resource with a WS-Federation Authentication Scheme › Configure a Unique Realm for Each WS-Fed Authentication Scheme
Configure a Unique Realm for Each WS-Fed Authentication Scheme
The procedure for configuring a unique realm for each WS-Federation authentication scheme (artifact or profile) follows the standard instructions for creating realms in the FSS Administrative UI.
To create a realm for each WS-Federation authentication scheme
- Log on to the FSS Administrative UI.
- Click the System tab.
- Click Edit, System Configuration, Create Domain.
The Domain dialog opens.
- Create a policy domain.
- Create a realm under the policy domain from the previous step, noting the following:
- Select the Web Agent protecting the web server where the target federation resources reside for the Agent field.
- Select the WS-Federation authentication scheme for the Authentication Scheme field. This authentication scheme protects the realm.
- Create a rule for the realm.
As part of the rule you select a Web Agent action (Get, Post, or Put), which allows you to control processing when users authenticate to gain access to a resource.
- Configure the policy, using the realm you created.
- Save the policy.
- Exit the FSS Administrative UI.
Note: Click Help for descriptions of settings and controls, including their respective requirements and limits.
A policy with a unique realm now protects the federated resource.
Copyright © 2012 CA.
All rights reserved.
|
|