From ICIHelp8.2
Jump to: navigation, search
(Created page with " With improved security, exchanging sensitive data across Id Provider (IdP) and Service Provider (SP) becomes more authenticated and trustworthy. This prevents intervention of...")
 
 
Line 2: Line 2:
 
With improved security, exchanging sensitive data across Id Provider (IdP) and Service Provider (SP) becomes more authenticated and trustworthy. This prevents intervention of any malicious party. Administrator or Implementation Partner can choose between the following SAML2 Binding types for request and response message exchange on the IdP server side.  
 
With improved security, exchanging sensitive data across Id Provider (IdP) and Service Provider (SP) becomes more authenticated and trustworthy. This prevents intervention of any malicious party. Administrator or Implementation Partner can choose between the following SAML2 Binding types for request and response message exchange on the IdP server side.  
  
*
+
*HTTP Redirect Binding   
HTTP Redirect Binding 
+
*HTTP POST Binding   
 
+
*HTTP Artifact Binding (newly added in 8.2 release)  
*
+
HTTP POST Binding 
+
 
+
*
+
HTTP Artifact Binding (newly added in 8.2 release)
+
  
 +
 
  
 
= Prerequisites  =
 
= Prerequisites  =
Line 26: Line 22:
 
#Open ADFS Management console.   
 
#Open ADFS Management console.   
 
#Ensure “/adfs/services/trust/artifactresolution” service is Enabled.   
 
#Ensure “/adfs/services/trust/artifactresolution” service is Enabled.   
<div class="image-green-border">[[File:AF 01.png|720px]]</div> <div class="image-green-border">&nbsp;</div>  
+
<div class="image-green-border">[[File:AF 01.png|720px|AF 01.png]]</div> <div class="image-green-border">&nbsp;</div>  
 
&nbsp; &nbsp; &nbsp; 3. Select the configured Relaying Party Trusts. Click “Properties”
 
&nbsp; &nbsp; &nbsp; 3. Select the configured Relaying Party Trusts. Click “Properties”
 
+
<div class="image-green-border">[[File:AF 02.png|RTENOTITLE]]</div>
[[File:AF 02.png]]
+
 
+
 
&nbsp; &nbsp; &nbsp; &nbsp; 4. Click “Add SAML…”&nbsp;
 
&nbsp; &nbsp; &nbsp; &nbsp; 4. Click “Add SAML…”&nbsp;
 
+
<div class="image-green-border">[[File:AF 03.png|RTENOTITLE]]</div>
[[File:AF 03.png]]
+
 
+
 
&nbsp; &nbsp; &nbsp; &nbsp; 5. Select Binding as “Artifact”. Check “Set the trusted URL as default”. Enter “Index” as unique no and “Trusted URL” should be exact match with service provider URL and should not have “/” at the end. Click “Ok”&nbsp;
 
&nbsp; &nbsp; &nbsp; &nbsp; 5. Select Binding as “Artifact”. Check “Set the trusted URL as default”. Enter “Index” as unique no and “Trusted URL” should be exact match with service provider URL and should not have “/” at the end. Click “Ok”&nbsp;
 
+
<div class="image-green-border">[[File:AF 04.png|RTENOTITLE]]</div>
[[File:AF 04.png]]
+
 
+
 
&nbsp; &nbsp; &nbsp; &nbsp; 6. Select Secure hash algorithm as SHA-1 &nbsp;
 
&nbsp; &nbsp; &nbsp; &nbsp; 6. Select Secure hash algorithm as SHA-1 &nbsp;
 
+
<div class="image-green-border">[[File:AF 05.png|RTENOTITLE]]</div>
[[File:AF 05.png]]
+

Latest revision as of 09:31, 5 September 2022

With improved security, exchanging sensitive data across Id Provider (IdP) and Service Provider (SP) becomes more authenticated and trustworthy. This prevents intervention of any malicious party. Administrator or Implementation Partner can choose between the following SAML2 Binding types for request and response message exchange on the IdP server side.  

  • HTTP Redirect Binding 
  • HTTP POST Binding 
  • HTTP Artifact Binding (newly added in 8.2 release)

 

Prerequisites 

Customer shares ADFS SAML2 Metadata URL with ICI. 

SAML 2 is already configured at Customer ADFS.  

Configuration

This section provides the steps to follow to enable Artifact Binding with ADFS by Administrator or Implementation Partner. 

Note - Depending on the ADFS configuration of the customer, the integration may differ slightly. 

This section provides the steps to be followed to enable Artifact Binding with ADFS. 

  1. Open ADFS Management console. 
  2. Ensure “/adfs/services/trust/artifactresolution” service is Enabled. 
AF 01.png
 

      3. Select the configured Relaying Party Trusts. Click “Properties”

RTENOTITLE

        4. Click “Add SAML…” 

RTENOTITLE

        5. Select Binding as “Artifact”. Check “Set the trusted URL as default”. Enter “Index” as unique no and “Trusted URL” should be exact match with service provider URL and should not have “/” at the end. Click “Ok” 

RTENOTITLE

        6. Select Secure hash algorithm as SHA-1  

RTENOTITLE