Configuring Remote Identity Provider

Last Updated : Feb 11, 2013 |

Procedure

  1. Download the XML metadata from the Identity Provider:
    1. Download the metadata in XML format that contains the service descriptor information of Remote Identity Provider (R-IDP) from the R-IDP server or using a valid HTTP URL that R-IDP provides.

      For example, if OpenAM is configured as the R-IDP, download the metadata from https://my-openam.ca.avaya.com/opensso/saml2/jsp/exportmetadata.jsp.

    2. Save the data in an XML file on the file system or save the URL that points to the metadata.
  2. Setup SSL trust between R-IDP and System Manager for successful communication of SAML messages using the following steps:
    1. On System Manager Web Console, click Services > Inventory.
    2. In the left navigation pane, click Manage Elements and add the CA certificate of R-IDP Web server certificate to System Manager truststore using the instructions outlined in Adding trusted certificates.
  3. Add Remote Identity Provider:
  4. Click Save.

    On successful configuration of R-IDP, the system automatically enables the SAML authentication. An administrator can disable or enable the SAML authentication using the Provision SAML Remote Identity Provider check box.