You can configure the methods of communication that are available at the server for requests and responses sent between providers. These settings affect the server metadata, so you must determine these prior to publishing to other sites.
Profiles control these methods of communication. An identity provider uses the incoming metadata to determine how to respond.
All available profile bindings are enabled by default. SOAP is used when all profile bindings are enabled (or if the service provider has not specified a preference), followed by HTTP Post, then HTTP Redirect.
Click Devices > Identity Servers > Edit > SAML 2.0 > Profiles.
Specify the following details for identity providers and identity consumers (service providers):
Field |
Description |
---|---|
Artifact Resolution |
Select to enable artifact resolution for the identity provider and identity consumer. The assertion consumer service at the service provider performs a back-channel exchange with the artifact resolution service at the identity provider. Artifacts are small data objects pointing to larger SAML protocol messages. These are embedded in URL and conveyed in HTTP messages. |
Login |
The communication channel to use when a user logs in. Select one or more of the following options:
|
Single Logout |
The communication channel to use when a user logs out. Select one or more of the following options:
|
Name Management |
Specifies the communication channel for sharing the common identifiers for a user between identity providers and service providers. When an identity provider has exchanged a persistent identifier for the user with a service provider, the providers share the common identifier for a length of time. When either the identity provider or service provider changes the format or value to identify the user, the system can ensure that the new format or value is properly transmitted. Select one or more of the following options:
|
Click OK.
Update Identity Server.
(Conditional) If you have set up trusted providers and modified these profiles, reimport providers’ metadata from this Identity Server.