SAML Federation tracing, logging, auditing, filtering and capturing configuration in Policy Server
search cancel

SAML Federation tracing, logging, auditing, filtering and capturing configuration in Policy Server

book

Article ID: 393141

calendar_today

Updated On:

Products

SITEMINDER CA Single Sign On Federation (SiteMinder)

Issue/Introduction


Running Policy Server, how to log traces of Federation journey, only for specific Partnership, and capturing and filtering the SAML documents or assertion?

 

Resolution


Enabling the Policy Server traces will allow to achieve that.

The traces are configured by the Profiler of the Policy Server.

The Profiler allows you to:

  • Select the aspect of the trace to capture. For Federation, enabling the component "Fed_Server" will write the SAML processing;
  • Apply some Filters, where the Partnership name can be set.

There are already templates to start with, from the config/profiler_templates (1):

  • samlidp_trace.template
      
    Provides the options for tracing the SAML Identity Provider assertions;

  • samlsp_trace.template
      
    Provides the options for tracing SAML Service Provider Authentication.

The filter pane should be configured with case sensitive values (2).

 

Additional Information