Sun OpenSSO Enterprise 8.0 Deployment Planning Guide

Setting Up and Configuring Secure Attributes Exchange

Before configuring and using the Secure Attributes Exchange, administrators must make some decisions regarding security-related settings such as cryptography type, applicable keys, and application identifiers. Administrators must be familiar with basic SAMLv2 concepts and the SAMLv2 samples bundled with OpenSSO Enterprise.

This section provides a high-level summary you need to resolve before configuring Secure Attributes Exchange.

About Cryptography Type

Secure Attributes Exchange provides symmetric and asymmetric cryptography types to secure identity attributes between an instance of OpenSSO Enterprise and an application.

Overview of Setup Steps

  1. Establish trust among the application or multiple applications and the instance of OpenSSO Enterprise on the Identity Provider. This includes the configuring the cryptography type, applicable keys, and application identifiers.

  2. Establish trust among the application or multiple applications and the instance of OpenSSO Enterprise on the Service Provider side. This includes configuring the cryptography type, applicable keys, and application identifiers.

  3. (Optional) The following steps are specific to using SAMLv2 with auto-federation.

    1. Determine which identity attributes you want transferred as part of the SAMLv2 single sign-on interaction.

    2. Determine which attribute you will use to identify the user on the Service Provider side.

  4. Determine which URL on the Service Provider will be responsible for handling logout requests from the Identity Provider.