Option 2: Configuring single sign-on based on IBM Lightweight Third-Party Authentication
You can configure single sign-on based on IBM Lightweight Third-Party Authentication(LTPA)with ® IBM Security Access Manager for Web.
Before you begin
- server.xml
- installation_dir/wlp/usr/servers/server1
- installation_dir\wlp\usr\servers\server1
- web.xml
- installation_dir/wlp/usr/servers/server1/apps/tema.war/WEB-INF
- installation_dir\wlp\usr\servers\server1\apps\tema.war\WEB-INF
About this task
Procedure
- Configure the connection to your directory server.
- Create
the users that will be authenticated with the single sign-on
server. You must create at least one user that has the Administrator
role.Important: Ensure that you select Single Sign-on from the Authenticated method drop-down list.
- Export the LDAP server SSL certificate embedded in BigFix® IBM Security Access Manager for Web.
- Configure LTPA single sign-on in BigFix Inventory web user interface.
- Import the LTPA keys into BigFix® Security Access Manager for Web.
- Import the BigFix Inventory server certificate into BigFix® Security Access Manager for Web.
- Configure a Virtual Junction in BigFix® IBM Security Access Manager for Web.
- Enable single sign-on in BigFix Inventory.
- Optional: Update the WebUI shortcut (Windows only)
- Optional:
Reverting SSO configuration for LTPA.
You can revert to the default LTPA SSO configuration with single sign-on disabled if there are problems with logging in to the application.