This topic tells you how to set up Layer7 SiteMinder as your identity provider by configuring SAML integration in both Tanzu Operations Manager and Layer7 SiteMinder.
To set up Layer7 SiteMinder as your identity provider through SAML integration:
Follow the steps in Configure SAML Settings.
To create an entity:
Sign in as a Layer7 SiteMinder admin.
Click the Federation tab.
Click on the Entities link.
Click Create Entity.
Select Local for Entity Location.
Select SAML2 IDP for New Entity Type.
Click Next.
To configure the entity in the Entities section:
Enter an Entity ID.
Enter an Entity Name.
Enter a Description.
Enter the URL for your Layer7 SiteMinder as the Base URL.
Select or import a Signing Private Key Alias.
Select a Name ID format.
Click Next.
Confirm the Entity Details and click Finish.
To import the metadata you downloaded earlier in the Configure SAML Settings procedure:
Click the Federation tab.
Click the Entities link.
Click Import Metadata.
Click Browse and select the downloaded metadata for Metadata file.
Select Remote Entity for Import As.
Select Create New for Operation.
Click Next.
In the Select Entity Defined in Metadata File section, fill in the Entity Name field and then click Next.
In the Select Key Entries to Import section, fill in the Alias field and then click Next.
Click Finish.
To create a partnership:
Click on the Federation tab.
Click Create Partnership and select SAML2 IDP -> SP.
To configure the partnership in the Configure Partnership section:
Enter a Partnership Name.
Enter a Description.
Select a previously created local entity for Local IDP.
Select a previously created remote entity for Remote SP.
Enter a Skew Time.
Add any User Directories.
Click Next.
To add federation users:
Add the users you want to include in the partnership.
Click Next.
To configure the assertion:
Select a Name ID Format.
Select User Attribute as the Name ID Type.
Enter mail
as the Value.
(Optional) Under Assertion Attributes, specify any app or group attributes that you want to map to users in the ID token. The value for sending a user’s groups is FMATTR:SM_USERGROUPS
.
Click Next.
To configure the SSO and SLO in the SSO and SLO section:
Enter the Authentication URL.
Select HTTP-Post for SSO Binding.
Select Both IDP and SP initiated for Transactions Allowed.
Click Next.
To configure the signature and encryption in the Signature and Encryption section:
Select your key alias for Signing Private Key Alias.
Select your certificate alias for Verification Certificate Alias.
Click Next.
Click Finish.
Click the Action dropdown and select Activate.
Click the Action dropdown and select Export Metadata to obtain the metadata needed for the Configuring a Single Sign-On Service Provider procedure.