Introduktion
Nærværende dokument beskriver konfigurationen af Acubiz EMS som en Relying Party Trust i Microsoft Active Directory Federation Services (AD FS). Opsætningen sikrer, at virksomhedens brugere kan tilgå Acubiz EMS via Single Sign-On (SSO).
Indhold i denne artikel:
- 1. Fremsendelse af Federation Metadata til Acubiz
- 2. Configuration of Acubiz EMS as Relying Party Trust
- 3. Test the SSO connection
1. Fremsendelse af Federation Metadata til Acubiz
Først skal virksomhedens FederationMetadata.xml-fil eller tilhørende URL fremsendes til Acubiz Support.
Fremgangsmåde for udtræk af Federation Metadata:
-
Åbn en browser og hent filen
FederationMetadata.xmldirekte fra virksomhedens AD FS-platform.URL-struktur:
https://adfs.[virksomhedsdomæne].com/federationmetadata/2007-06/federationmetadata.xml -
Fejlfinding ved manglende adgang:
Hvis metadatafilen ikke kan tilgås, skal du kontrollere, at Metadata endpoint er aktiveret i AD FS:
Åbn AD FS Management.
Naviger til AD FS > Service > Endpoints.
Find sektionen Metadata og bekræft, at endpointet står som Enabled.
Bemærk: I stedet for manuelt at sende XML-filen kan du fremsende det direkte link (URL) til filen, forudsat at denne er offentligt tilgængelig.
2. Configuration of Acubiz EMS as Relying Party Trust
General configuration
- Open AD FS Management à Add Relying Party Trust
Click the [Start]-button in the window
-
Select “Import data about the relying party published online or on local network” and
insert the following URL in the address field:https://auth.acubiz.com/federationmetadata/2007-06/federationmetadata.xml
Click the [Next]-button
- Enter ”Acubiz” as Display name
Click the [Next]-button
- Check that “I do not want to configure…” is selected:
Click the [Next]-button
- Check that “Permit all users to access this relying party” is selected:
Click the [Next]-button
Should you wish to limit access to Acubiz EMS for specific users, then this can later be
configured in the Claim Rule view under ”Issuance Authorization Rules”.
Click the [Next]-button
Click the [Close]-button
Configuration of Claim Rules
This section describes the Claim Rules required to connect to Acubiz:
Click the [Add Rule…]-button
Set up AD Attributes
Select ”Send LDAP Attributes as Claims”:
Click the [Next]-button.
Configure LDAP attributes
Configure the LDAP Attribute store to send Claim Types as follows:
| LDAP Attribute | Required outgoing Claim Type (Name) |
| Display-Name | http://schemas.xmlsoap.org/claims/CommonName |
| E-Mail-Addresses | http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress |
| E-Mail-Addresses | http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
The Claim type “name” is required and must contain the User email address!
Click the [OK]-button
3. Test the SSO connection
Now Test of SSO connection to Acubiz
Kommentarer
0 kommentarer
Log ind for at kommentere.