SAML Service Provider without User Directory configuration
search cancel

SAML Service Provider without User Directory configuration

book

Article ID: 282177

calendar_today

Updated On:

Products

SITEMINDER CA Single Sign On Federation (SiteMinder) CA Single Sign On Secure Proxy Server (SiteMinder)

Issue/Introduction


Running CA Access Gateway (SPS) for Federation Services, acting as SP, is it possible to run your Service Provider (SP) side, without configuring a User Directory?

 

Resolution


No. Unfortunately, it's impossible, as Federation relies on sharing the identity of the user from both sides.

Both Partners, Identity Provider (IdP) and Service Provider (SP), define together an agreement, how the user will be found on each side. This is how Federation is built.

Both sides should have a User Directory where to find the user:

     Account linking can be used for browser-based single sign-on, where
     each partner maintains separate user accounts for the same user. (1)

     Partnership federation looks up entries in a user directory to
     verify identities and retrieve user attributes for a given
     principal. At the asserting party, the federation partner
     generates assertions for the appropriate users, and authenticates
     each user against a user directory. At the relying party, the
     federation partner extracts the necessary information from an
     assertion and looks in the user directory for the appropriate
     user record. (2)

 

Additional Information