Previous Topic: Prerequisites Before Integrating SiteMinder and CA SSO

Next Topic: Configure Single Sign-On from CA SSO Client to SiteMinder

Configure Single Sign-On from SiteMinder to CA SSO

SiteMinder provides single sign-on from SiteMinder to CA SSO environments.

To enable single sign-on from SiteMinder to CA SSO

Web Agent or Secure Proxy Server Configuration Steps

Enable the SiteMinder SSO Plug-in installed with the Web Agent or Secure Proxy Server:

For the 6.x QMR 4 IIS 6.0 or Apache 2.0 Web Agent

Note: After you modify the WebAgent.conf file, restart the Web server if it is running so that the new configuration settings take effect.

For the 6.0 Secure Proxy Server

Note: After you modify the WebAgent.conf file, restart the Secure Proxy Server if it is running so that the new configuration settings take effect.

CA WAC Web Agent Verification Steps

  1. Configure the domain in the CA WAC Web Agent’s webagent.ini file by setting the following parameter:

    DomainCookie=<domain>

    where <domain> is the same domain (for example, test.com) for the CA SSO and SiteMinder Web Agents.

    The file is installed in the following location on the CA WAC Web Agent machine:

    C:\Program Files\CA\WebAccessControl\WebAgent\webagent.ini

  2. Verify the following Web server and the authentication method settings in the webagent.ini file:

CA SSO Policy Manager Verification Steps

  1. Ensure that the SiteMinder and CA SSO Policy Servers use the same user or authentication store.
  2. Make sure you have the following:

Policy Server Configuration Steps

  1. Create a Web Agent, Agent Configuration Object, and Host Configuration Object using the Policy Server User Interface. For more information, see the Policy Server Installation Guide and Web Agent Installation Guide.
  2. Configure the SiteMinder and CA SSO Policy Servers to use the same user or authentication store.

    For SiteMinder user store configuration instructions, see this guide.

    For the CA SSO authentication store, see the CA SSO documentation.

  3. Configure an smetssocookie (certificate) custom active response.
  4. Create a domain, realm, and rules using the Policy Server User Interface to protect any resource with the SiteMinder Web Agent.

    Note: When creating the rules, append the smetssocookie custom active response to them.

Overall Verification Steps

  1. Configure the user with credentials to access resources protected by the SiteMinder Web Agent and the CA WAC Web Agent.
  2. Restart the SiteMinder Policy Server and Web server hosting the Policy Server User Interface.
  3. Access the resource protected by the SiteMinder Web Agent and provide this Web Agent with the appropriate user credentials.
  4. After gaining access to this resource, in the same browser session, request a resource protected by the CA WAC Web Agent.

    You should gain access to this resource without being prompted for credentials.

More information:

Configure an smauthetsso Custom Authentication Scheme

Configure an smetssocookie Web Agent Active Response Attribute

Domains

Grouping Resources in Realms

Rules

Configure a Rule for Web Agent Actions