Sun Java System Access Manager 7.1 Federation and SAML Administration Guide
    
A
 
 access
  Authentication Web Service ( Index Term Link )
  Discovery Service ( Index Term Link )
  Liberty Personal Profile Service ( Index Term Link )
 
 Access Manager
  and federation ( Index Term Link )
  architecture ( Index Term Link )
  documentation ( Index Term Link )
  implementation of Liberty Alliance Project ( Index Term Link )
  Liberty-based web services ( Index Term Link )
 
 account federation, definition ( Index Term Link )
 
 affiliate entity
  See also entities
  configuring ( Index Term Link )
  definition ( Index Term Link )
 
 affiliation, definition ( Index Term Link )
 
 amadmin, create entities ( Index Term Link )
 
 ambulkfed, See bulk federation
 
 amDisco_add.xml ( Index Term Link )
 
 amDisco.xml ( Index Term Link )
 
 amSAML.xml ( Index Term Link )
 
 API
  Authentication Web Service ( Index Term Link )
  client for Discovery Service ( Index Term Link )
  common security ( Index Term Link )
  common service ( Index Term Link )
  Data Services Template ( Index Term Link ) ( Index Term Link )
  Discovery Service ( Index Term Link )
  extract ( Index Term Link )
  federation ( Index Term Link )
  Interaction Service ( Index Term Link )
  PAOS binding ( Index Term Link )
  public interfaces ( Index Term Link )
  SAML ( Index Term Link )
  SOAP Binding Service ( Index Term Link )
 
 Application Server, documentation ( Index Term Link )
 
 architecture
  Discovery Service ( Index Term Link )
  Liberty Alliance Project in Access Manager ( Index Term Link )
  SAML ( Index Term Link )
 
 Artifact Timeout ( Index Term Link )
 
 asserting party ( Index Term Link )
 
 assertion consumer ( Index Term Link )
 
 Assertion Skew Factor For notBefore Time ( Index Term Link )
 
 Assertion Timeout ( Index Term Link )
 
 assertion types, and SAML ( Index Term Link )
 
 Attribute Mapper ( Index Term Link )
 
 attribute provider, definition ( Index Term Link )
 
 attributes
  authentication context classes ( Index Term Link )
  Authentication Web Service ( Index Term Link )
  communication profiles ( Index Term Link )
  communication URLs ( Index Term Link )
  context reference ( Index Term Link )
  default authentication context ( Index Term Link )
  Discovery Service ( Index Term Link )
  identity provider attribute mapping ( Index Term Link )
  Liberty Personal Profile Service ( Index Term Link )
  protocol support enumeration ( Index Term Link )
  proxy configuration ( Index Term Link )
  server name identifier mapping binding ( Index Term Link )
  SOAP Binding Service ( Index Term Link )
 
 authentication context ( Index Term Link )
  attribute ( Index Term Link ) ( Index Term Link )
  definition ( Index Term Link )
  overview ( Index Term Link )
 
 authentication domain
  create ( Index Term Link )
  definition ( Index Term Link )
 
 authentication domains
  configure or modify ( Index Term Link )
  create ( Index Term Link )
  delete ( Index Term Link )
  overview ( Index Term Link )
 
 Authentication Service (non-Liberty) ( Index Term Link )
 
 Authentication Service Specification, overview ( Index Term Link )
 
 authentication services
  Authentication Service (non-Liberty) ( Index Term Link )
  Authentication Web Service (Liberty) ( Index Term Link )
 
 Authentication Web Service
  accessing ( Index Term Link )
  API ( Index Term Link )
  attribute ( Index Term Link )
  extract ( Index Term Link )
  or Authentication Service (non-Liberty) ( Index Term Link )
  overview ( Index Term Link )
  process ( Index Term Link )
  sample ( Index Term Link ) ( Index Term Link )
  XML service file ( Index Term Link )
 
 Authorizer ( Index Term Link )
 
 Authorizer interface ( Index Term Link )
 
 Authorizer interface ( Index Term Link )
 
 auto-federation ( Index Term Link ) ( Index Term Link )
    
B
 
 basic authentication ( Index Term Link )
 
 binding, definition ( Index Term Link )
 
 bootstrapping discovery service ( Index Term Link )
 
 bootstrapping Discovery Service ( Index Term Link )
 
 bulk federation ( Index Term Link ) ( Index Term Link )
 
 business agreements ( Index Term Link )
    
C
 
 circle of trust, definition ( Index Term Link )
 
 client, definition ( Index Term Link )
 
 client API
  Data Services Template ( Index Term Link )
  Discovery Service ( Index Term Link )
 
 Client Profiles Specification, overview ( Index Term Link )
 
 com.sun.identity.federation.plugins ( Index Term Link )
 
 com.sun.identity.federation.services ( Index Term Link )
 
 com.sun.identity.liberty.wsf.version ( Index Term Link )
 
 com.sun.liberty ( Index Term Link )
 
 common domain
  definition ( Index Term Link )
  overview ( Index Term Link )
 
 common domain cookie ( Index Term Link )
 
 common domain services
  configure properties ( Index Term Link )
  configure URLs ( Index Term Link )
  installation ( Index Term Link )
 
 common security API ( Index Term Link )
 
 common service interfaces ( Index Term Link )
 
 communication profiles ( Index Term Link )
 
 communication URLs ( Index Term Link )
 
 containers ( Index Term Link )
 
 context reference attribute ( Index Term Link )
 
 cookie, common domain ( Index Term Link )
 
 create
  authentication domains ( Index Term Link )
  entities ( Index Term Link )
 
 create entities, with amadmin ( Index Term Link )
 
 customize
  federation ( Index Term Link )
  graphical user interface ( Index Term Link )
    
D
 
 data services
  See also Data Services Template
  API ( Index Term Link )
  developing ( Index Term Link )
  Liberty Employee Profile Service ( Index Term Link )
  Liberty Personal Profile Service ( Index Term Link )
  overview ( Index Term Link )
 
 Data Services Template ( Index Term Link )
  API ( Index Term Link )
  client API ( Index Term Link )
 
 Data Services Template Specification, overview ( Index Term Link )
 
 default authentication context attribute ( Index Term Link )
 
 Default64ResourceIDMapper ( Index Term Link )
 
 DefaultDiscoAuthorizer class ( Index Term Link )
 
 DefaultHexResourceIDMapper ( Index Term Link )
 
 defederation, definition ( Index Term Link )
 
 definitions
  federation ( Index Term Link )
  identity ( Index Term Link )
  identity federation ( Index Term Link )
  Liberty Alliance Project terms ( Index Term Link )
  provider federation ( Index Term Link )
 
 develop web services
  hosting ( Index Term Link )
  invoke ( Index Term Link )
  process ( Index Term Link )
 
 developing data services ( Index Term Link )
 
 digital certificates ( Index Term Link )
 
 digital signatures ( Index Term Link )
 
 Directory Server, documentation ( Index Term Link )
 
 DiscoEntryHandler interface ( Index Term Link )
 
 Discovery Service
  accessing ( Index Term Link )
  and policy creation ( Index Term Link )
  and security tokens ( Index Term Link )
  API ( Index Term Link )
  architecture ( Index Term Link )
  attributes ( Index Term Link )
  bootstrapping ( Index Term Link )
 
 discovery service, bootstrapping ( Index Term Link )
 
 Discovery Service
  client API ( Index Term Link )
  extract ( Index Term Link )
  overview ( Index Term Link )
  process ( Index Term Link )
  resource offerings ( Index Term Link )
  sample ( Index Term Link )
  XML service files ( Index Term Link )
 
 Discovery Service Specification, overview ( Index Term Link )
 
 documentation
  Access Manager ( Index Term Link )
  Application Server ( Index Term Link )
  Directory Server ( Index Term Link )
  Sun Java Enterprise System ( Index Term Link )
  Sun Java System ( Index Term Link )
  Web Proxy Server ( Index Term Link )
  Web Server ( Index Term Link )
 
 dynamic identity provider proxying ( Index Term Link ) ( Index Term Link )
    
E
 
 employee profile service sample ( Index Term Link )
 
 entities
  configuring affiliate ( Index Term Link )
  configuring provider ( Index Term Link )
  creating ( Index Term Link )
  creating with amadmin ( Index Term Link )
  overview ( Index Term Link )
  populate ( Index Term Link )
 
 entity descriptors, See entities
    
F
 
 federated identity, definition ( Index Term Link )
 
 federation
  affiliate entity
   configuring ( Index Term Link )
  and single sign-on ( Index Term Link )
  API ( Index Term Link )
  authentication domains ( Index Term Link )
  auto-federation ( Index Term Link )
  bulk federation ( Index Term Link )
  configure global logout ( Index Term Link )
  configure pre-login ( Index Term Link )
  definition ( Index Term Link ) ( Index Term Link )
  dynamic identity provider proxying ( Index Term Link )
  entities ( Index Term Link )
   creating ( Index Term Link )
   creating with amadmin ( Index Term Link )
  entities and authentication domains ( Index Term Link )
  graphical user interface ( Index Term Link )
  identity provider metadata sample ( Index Term Link )
  in Access Manager ( Index Term Link )
  pre-login process ( Index Term Link )
  pre-login URL ( Index Term Link )
  process of ( Index Term Link )
  provider entity
   configuring ( Index Term Link )
  sample environment ( Index Term Link )
  samples ( Index Term Link )
  service provider metadata sample ( Index Term Link )
  signing ( Index Term Link )
 
 federation API ( Index Term Link )
 
 federation cookie, definition ( Index Term Link )
 
 federation termination, definition ( Index Term Link )
 
 Federation Termination Notification Protocol, overview ( Index Term Link )
 
 FSConfig.properties ( Index Term Link )
    
G
 
 global logout ( Index Term Link )
  configure ( Index Term Link )
 
 Glossary, Java ES ( Index Term Link )
 
 graphical user interface, federation ( Index Term Link )
    
I
 
 identifiers and name registration ( Index Term Link )
 
 identity
  definition ( Index Term Link ) ( Index Term Link )
 
 identity-based web service ( Index Term Link )
 
 identity federation ( Index Term Link )
  definition ( Index Term Link ) ( Index Term Link )
 
 identity provider
  definition ( Index Term Link )
  metadata sample ( Index Term Link )
 
 identity provider attribute mapping ( Index Term Link )
 
 identity providers, trust between ( Index Term Link )
 
 identity service
  definition ( Index Term Link ) ( Index Term Link )
 
 installation, common domain services ( Index Term Link )
 
 Interaction Service ( Index Term Link )
 
 Interaction Service Specification, overview ( Index Term Link )
 
 interfaces
  Authentication Web Service ( Index Term Link )
  Authorizer ( Index Term Link )
  Authorizer ( Index Term Link )
  common service ( Index Term Link )
  DiscoEntryHandler ( Index Term Link )
  Discovery Service ( Index Term Link )
  request handler ( Index Term Link )
  ResourceIDMapper ( Index Term Link )
  ResourceIDMapper ( Index Term Link )
    
K
 
 key management ( Index Term Link )
  keystore entry ( Index Term Link )
  overview ( Index Term Link )
  setting up keystore ( Index Term Link )
  trusted certificate entry ( Index Term Link )
 
 keystore, setting up ( Index Term Link )
 
 keystore entry ( Index Term Link ) ( Index Term Link )
 
 keytool ( Index Term Link )
    
L
 
 Liberty Alliance Project
  architecture in Access Manager ( Index Term Link )
  Liberty Identity Federation Framework ( Index Term Link )
  Liberty Identity Service Interface Specifications ( Index Term Link )
  Liberty Identity Web Services Framework ( Index Term Link )
  overview ( Index Term Link )
  SAML comparison ( Index Term Link )
  specifications ( Index Term Link )
  terms ( Index Term Link )
 
 Liberty-based API ( Index Term Link )
 
 Liberty-based web services, Access Manager ( Index Term Link )
 
 Liberty Employee Profile Service ( Index Term Link )
 
 Liberty-enabled client, definition ( Index Term Link )
 
 Liberty-enabled proxy, definition ( Index Term Link )
 
 Liberty ID-FF Bindings and Profiles, overview ( Index Term Link )
 
 Liberty ID-FF Protocols and Schema, overview ( Index Term Link )
 
 Liberty ID-SIS Employee Profile Service Specification, overview ( Index Term Link )
 
 Liberty ID-SIS Personal Profile Service Specification, overview ( Index Term Link )
 
 Liberty ID-WSF, implementation ( Index Term Link )
 
 Liberty ID-WSF 1.1 profiles ( Index Term Link )
 
 Liberty Identity Federation Framework
  convergence with SAML ( Index Term Link )
  overview ( Index Term Link )
 
 Liberty Identity Service Interface Specifications, overview ( Index Term Link )
 
 Liberty Identity Web Services Framework, overview ( Index Term Link )
 
 Liberty Personal Profile Service ( Index Term Link )
  accessing ( Index Term Link )
  attributes ( Index Term Link )
  extract ( Index Term Link )
 
 Liberty process sample ( Index Term Link )
    
M
 
 metadata ( Index Term Link )
  identity provider sample ( Index Term Link )
  service provider sample ( Index Term Link )
    
N
 
 name identifier, definition ( Index Term Link )
 
 Name Identifier Mapping Protocol, overview ( Index Term Link )
 
 name registration ( Index Term Link )
 
 Name Registration Protocol, overview ( Index Term Link )
    
O
 
 overview
  authentication and authentication context ( Index Term Link )
  authentication domains ( Index Term Link )
  Authentication Service Specification ( Index Term Link )
  Authentication Web Service ( Index Term Link )
  auto-federation ( Index Term Link ) ( Index Term Link )
  bulk federation ( Index Term Link ) ( Index Term Link )
  Client Profiles Specification ( Index Term Link )
  common domain ( Index Term Link )
  common domain cookie ( Index Term Link )
  common domain services
   properties ( Index Term Link )
   URLs ( Index Term Link )
  data services ( Index Term Link )
  Data Services Template ( Index Term Link )
  Data Services Template Specification ( Index Term Link )
  Discovery Service ( Index Term Link )
  Discovery Service Specification ( Index Term Link )
  dynamic identity provider proxying ( Index Term Link ) ( Index Term Link )
  entities ( Index Term Link )
  federation API ( Index Term Link )
  federation management ( Index Term Link )
  federation process ( Index Term Link )
  Federation Termination Notification Protocol ( Index Term Link )
  global logout ( Index Term Link )
  identifiers and name registration ( Index Term Link )
  identity federation and single sign-on ( Index Term Link )
  implementation of Liberty Alliance Project ( Index Term Link )
  Interaction Service ( Index Term Link )
  Interaction Service Specification ( Index Term Link )
  Liberty Alliance Project ( Index Term Link )
  Liberty Alliance Project specifications ( Index Term Link )
  Liberty Employee Profile Service ( Index Term Link )
  Liberty ID-FF Bindings and Profiles ( Index Term Link )
  Liberty ID-FF Protocols and Schema ( Index Term Link )
  Liberty ID-SIS Employee Profile Service Specification ( Index Term Link )
  Liberty ID-SIS Personal Profile Service Specification ( Index Term Link )
  Liberty Identity Federation Framework ( Index Term Link )
  Liberty Identity Service Interface Specifications ( Index Term Link )
  Liberty Identity Web Services Framework ( Index Term Link )
  Liberty Personal Profile Service ( Index Term Link )
  Name Identifier Mapping Protocol ( Index Term Link )
  Name Registration Protocol ( Index Term Link )
  PAOS binding ( Index Term Link )
  pre-login URL ( Index Term Link )
  public interfaces ( Index Term Link )
  SAML ( Index Term Link )
  samples ( Index Term Link )
  Security Mechanisms Specification ( Index Term Link )
  signing Liberty ID-FF ( Index Term Link )
  Single Logout Protocol ( Index Term Link )
  Single Sign-On and Federation Protocol ( Index Term Link )
  SOAP Binding Service ( Index Term Link )
  SOAP Binding Specification ( Index Term Link )
    
P
 
 PAOS binding ( Index Term Link )
  PAOS or SOAP ( Index Term Link )
  sample ( Index Term Link ) ( Index Term Link )
 
 parameters, pre-login URL ( Index Term Link )
 
 patches, Solaris ( Index Term Link )
 
 PKI ( Index Term Link )
  digital certificates ( Index Term Link )
  digital signatures ( Index Term Link )
 
 policy creation, and Discovery Service ( Index Term Link )
 
 pre-login, configure ( Index Term Link )
 
 pre-login process ( Index Term Link )
 
 pre-login URL ( Index Term Link )
  configure ( Index Term Link )
  parameters ( Index Term Link )
 
 principal, definition ( Index Term Link )
 
 procedures
  create policy for DefaultDiscoAuthorizer ( Index Term Link )
  store resource offerings ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 process
  Authentication Web Service ( Index Term Link )
  Discovery Service ( Index Term Link )
  federation ( Index Term Link )
  federation and single sign-on ( Index Term Link )
  pre-login ( Index Term Link )
  SOAP Binding Service ( Index Term Link )
 
 profile, definition ( Index Term Link )
 
 profile types
  and SAML ( Index Term Link )
  web artifact profile ( Index Term Link )
  web POST profile ( Index Term Link )
 
 profiles, set up Liberty ID-WSF ( Index Term Link )
 
 protocol, definition ( Index Term Link )
 
 protocol support enumeration ( Index Term Link )
 
 provider entity
  See also entities
  configuring ( Index Term Link )
  definition ( Index Term Link )
 
 provider federation
  definition ( Index Term Link ) ( Index Term Link )
  enable ( Index Term Link )
 
 provider trust ( Index Term Link ) ( Index Term Link )
 
 proxy configuration ( Index Term Link )
 
 pseudonym
  definition
   See name identifier
 
 public interfaces ( Index Term Link )
 
 public key infrastructure, See PKI
    
Q
 
 query parameter ( Index Term Link )
    
R
 
 reader service URL ( Index Term Link ) ( Index Term Link )
 
 receiver, definition ( Index Term Link )
 
 relying party ( Index Term Link )
 
 request handler ( Index Term Link )
 
 RequestHandler interface ( Index Term Link )
 
 resource offering ( Index Term Link )
  definition ( Index Term Link )
  for bootstrapping ( Index Term Link )
 
 resource offerings
  as dynamic attributes ( Index Term Link )
  as user attributes ( Index Term Link )
  storing ( Index Term Link )
 
 resource offerings for bootstrapping ( Index Term Link )
 
 ResourceID Mapper ( Index Term Link )
 
 ResourceIDMapper interface ( Index Term Link )
 
 ResourceIDMapper interface ( Index Term Link )
    
S
 
 SAML ( Index Term Link )
  amSAML.xml ( Index Term Link )
  API ( Index Term Link )
  architecture ( Index Term Link )
  Artifact Timeout ( Index Term Link )
  Assertion Skew Factor For notBefore Time ( Index Term Link )
  assertion types ( Index Term Link )
  AssertionTimeout ( Index Term Link )
  convergence with Liberty ID-FF ( Index Term Link )
  Liberty comparison ( Index Term Link )
  overview ( Index Term Link )
  profile types ( Index Term Link )
   web artifact profile ( Index Term Link )
   web POST profile ( Index Term Link )
  SAML Artifact Name ( Index Term Link )
  SAML SOAP receiver ( Index Term Link )
   SOAP messages ( Index Term Link )
  samples ( Index Term Link )
  Sign SAML Assertion ( Index Term Link )
  Sign SAML Request ( Index Term Link )
  Sign SAML Response ( Index Term Link )
  site Identifiers ( Index Term Link )
  Target Specifier ( Index Term Link )
  target URLs ( Index Term Link )
  trusted partners ( Index Term Link )
  using ( Index Term Link )
 
 SAML Artifact Name ( Index Term Link )
 
 SAML authority ( Index Term Link )
 
 SAML SOAP receiver ( Index Term Link )
  SOAP messages ( Index Term Link )
 
 sample use case ( Index Term Link )
 
 samples
  Authentication Web Service ( Index Term Link ) ( Index Term Link )
  Discovery Service ( Index Term Link )
  employee profile service ( Index Term Link )
  federation ( Index Term Link ) ( Index Term Link )
  PAOS binding ( Index Term Link ) ( Index Term Link )
  SAML ( Index Term Link )
  security tokens ( Index Term Link )
  use case process ( Index Term Link )
  web service consumer ( Index Term Link )
 
 samples overview ( Index Term Link )
 
 security, web services ( Index Term Link )
 
 Security Mechanisms Specification, overview ( Index Term Link )
 
 security tokens
  and Discovery Service ( Index Term Link )
  generating ( Index Term Link )
 
 sender, definition ( Index Term Link )
 
 server, definition ( Index Term Link )
 
 server name identifier mapping binding ( Index Term Link )
 
 service provider
  definition ( Index Term Link )
  metadata sample ( Index Term Link )
 
 service providers, trust between ( Index Term Link )
 
 Sign SAML Assertion ( Index Term Link )
 
 Sign SAML Request ( Index Term Link )
 
 Sign SAML Response ( Index Term Link )
 
 signing Liberty ID-FF ( Index Term Link )
 
 single logout, definition ( Index Term Link )
 
 Single Logout Protocol, overview ( Index Term Link )
 
 single sign-on ( Index Term Link )
  definition ( Index Term Link )
 
 Single Sign-On and Federation Protocol, overview ( Index Term Link )
 
 single sign—on, and federation ( Index Term Link )
 
 site identifiers ( Index Term Link )
 
 SOAP Binding, extract ( Index Term Link )
 
 SOAP Binding Service
  API ( Index Term Link )
  attributes ( Index Term Link )
  overview ( Index Term Link )
  PAOS or SOAP ( Index Term Link )
  process ( Index Term Link )
  request handler ( Index Term Link )
  SOAPReceiver ( Index Term Link )
  XML service file ( Index Term Link )
 
 SOAP Binding Specification, overview ( Index Term Link )
 
 SOAP messages ( Index Term Link )
 
 SOAPReceiver ( Index Term Link )
  SOAP Binding process ( Index Term Link )
 
 Solaris
  patches ( Index Term Link )
  support ( Index Term Link )
 
 specifications (Liberty Alliance Project) ( Index Term Link )
  Liberty Identity Federation Framework ( Index Term Link )
  Liberty Identity Service Interface Specifications ( Index Term Link )
  Liberty Identity Web Services Framework ( Index Term Link )
 
 support, Solaris ( Index Term Link )
    
T
 
 Target Specifier ( Index Term Link )
 
 target URLs ( Index Term Link )
 
 terms, Liberty Alliance Project ( Index Term Link )
 
 trust, between providers ( Index Term Link )
 
 trusted certificate entry ( Index Term Link )
 
 trusted partners ( Index Term Link )
 
 trusted provider, definition ( Index Term Link )
    
U
 
 use cases, sample process ( Index Term Link )
    
W
 
 web artifact profile ( Index Term Link )
 
 web POST profile ( Index Term Link )
 
 Web Proxy Server, documentation ( Index Term Link )
 
 Web Server, documentation ( Index Term Link )
 
 web service consumer, definition ( Index Term Link )
 
 web service consumer sample ( Index Term Link )
 
 web service provider, definition ( Index Term Link )
 
 web services
  developing ( Index Term Link )
  hosting ( Index Term Link )
  invoking ( Index Term Link )
  security ( Index Term Link )
 
 web services (Liberty-based), Access Manager ( Index Term Link )
 
 Web Services Description Language, See WSDL
 
 writer service URL ( Index Term Link ) ( Index Term Link )
 
 WSDL ( Index Term Link )
    
X
 
 XML service files
  amSAML.xml ( Index Term Link )
  Authentication Web Service ( Index Term Link )
  Discovery Service ( Index Term Link )
  SOAP Binding Service ( Index Term Link )