Sun Java System Access Manager 7.1 Federation and SAML Administration Guide

SAML Architecture in Access Manager

SAML security information is expressed in the form of an assertion about a subject. An assertion is a package of verified security information that supplies one or more statements concerning a subject’s authentication status, access authorization decisions, or identity attributes. Assertions are issued by the SAML authority, and received by partner sites defined by the authority as trusted. SAML authorities use different sources to configure the assertion information, including external data stores or assertions that have already been received and verified. The following figure illustrates how SAML interacts with the other components in Access Manager.


Note –

Although Federation (as described in Chapter 3, Federation) integrates aspects of the SAML specifications, its usage of SAML is independent of the SAML component as described in this chapter.


Figure 10–1 SAML Interaction in Access Manager

Graphic that illustrates SAML interaction within Access Manager

SAML allows Access Manager to work in the following ways: