Configuring SAML redirection services for web SSO
To gain SAML support for all IBM® Connections components accessed via a browser, set up SAML redirection services to use the default authenticator. This process replaces the web login page for Connections with your SAML Identity Provider (IdP) through the use of a redirect.
Before you begin
Install IBM Connections 5.5, CR1.
About this task
This SAML support has been tested with the following two SAML Identity
Providers (IdP):
Review the following table to understand the current level of SAML support (and its
limitations) in Connections and verify that your requirements can be met. If your requirements are
not clearly met, then do not proceed with configuring SAML. - TFIM - IBM TFIM 6.2.2, SAML 2.0 IdP only
- MS-ADFS - Microsoft™ ADFS 2.0, SAML 2.0 IdP only
Connections components accessed via a browser | SAML (within cell) and LTPA (outside cell) for Authentication, with LTPA for SSO |
---|---|
Connections web-based interface as follows:
|
Supported |
Integration with CCM/FileNet | Supported |
Integration with Metrics/Cognos | Supported |
All other components, which includes:
|
Not supported |
FileNet® administration user interfaces will not be protected by SAML following this configuration. Existing built-in login screens continue to protect FileNet administration user interfaces.
Refer to the following topics in the WebSphere Application Server information center to understand how to enable single sign-on
with SAML: