Configure CA Identity Manager as IdP
- In the miniOrange SAML 2.0 SSO plugin, navigate to Service Provider Metadata tab. Here, you can find the SP metadata such as SP Entity ID and ACS (AssertionConsumerService) URL which are required to configure the Identity Provider.
Note: For Single Sign On, make sure to install and setup CA SSO (formerly known as SiteMinder) with CA Identity Manager.
- Log in to your CA SSO portal as a CA Single Sign-On administrator.
- Click on Federation tab.
- Now go to Partnership FederationEntities.
Create a Local Identity Provider
- Click on Create Entity.
- To create a local entity, configure the following:
||Enter an ID for your local identity provider for identification.
||Create a name for your local identity provider.
||Enter the fully-qualified domain name for the host service CA SSO Federation Web Services.
|Signed Authentication Requests Required
|Supported NameID format
Create a Remote Service Provider
- Download Metadata XML File from the Service Provider Metadata Tab of the miniOrange SAML SSO plugin.
- Click on Import Metadata and upload the downloaded XML metadata file.
- For Import As, select Remote Entity.
- Provide a name for the Remote Service Provider Entity.
Create a Partnership between SP and IDP
- For creating a partnership, configure the following:
|Add Partnership Name
||Enter a name for your partnership.
||Enter a relevant description for your partnership.
|Local IDP ID
||Enter the Local Identity Provider ID created while adding a Local Entity.
|Remote SP ID
||Enter the Remote Service Provider ID created while adding a Remote Entity.
||This field will be pre-populated.
||Enter any skew time required by your environment.
|User Directories and Search Order
||Select the required directories in the required search order.
- On the Federation Users page, add the users you want to include in the partnership.
- In the Assertion Configuration section, configure following:
- Name ID Format: Email Address
- Name ID Type: User Attribute
- Value: mail
- (Optional) Assertion Attributes: Specify any application or group attributes that you want to map to users
- In the SSO and SLO section, perform the following steps:
- SSO Binding: HTTP-POST
- Transactions Allowed: Both IDP and SP initiated
- In the Signature and Encryption section, select Post Signature as Sign Both.
- In the Federation Partnership List, expand the Action dropdown for your partnership and click Activate.
- To get the IDP metadata, Click the Action button and click Export Metadata. This data will be used to configure the plugin.