Searching the Help
To search for information in the Help, type a word or phrase in the Search box. When you enter a group of words, OR is inferred. You can use Boolean operators to refine your search.
Results returned are case insensitive. However, results ranking takes case into account and assigns higher scores to case matches. Therefore, a search for "cats" followed by a search for "Cats" would return the same number of Help topics, but the order in which the topics are listed would be different.
Search for | Example | Results |
---|---|---|
A single word | cat
|
Topics that contain the word "cat". You will also find its grammatical variations, such as "cats". |
A phrase. You can specify that the search results contain a specific phrase. |
"cat food" (quotation marks) |
Topics that contain the literal phrase "cat food" and all its grammatical variations. Without the quotation marks, the query is equivalent to specifying an OR operator, which finds topics with one of the individual words instead of the phrase. |
Search for | Operator | Example |
---|---|---|
Two or more words in the same topic |
|
|
Either word in a topic |
|
|
Topics that do not contain a specific word or phrase |
|
|
Topics that contain one string and do not contain another | ^ (caret) |
cat ^ mouse
|
A combination of search types | ( ) parentheses |
|
- Install and configure the standalone IdM service
- Task 1: Deploy IdM on a web application server
- Task 2: Configure SSL in the IdM web application server
- Task 3: Create an IdM client trust store
- Task 4: Configure SAML SSO
- Task 5: Configure a tenant and specify the ADFS metadata URL
- Task 6: Configure the IdM service for LW-SSO compatibility
- Task 7: Specify an IdM token signing key
- Task 8: Specify an IdM user account for Service Manager
- Task 9: Replace JRE policy files for the IdM server
- Task 10: Configure the SAML keystore in IdM
- Task 11: Import the IdP public key into the IdM SAML keystore
- Task 12: Encrypt IdM passwords and keys
- Task 13: Create an empty database for IdM
- Task 14: Configure database connection in the IdM service
- Task 15: Download the IdM metadata
- Task 16: Create a trust relationship with ADFS
- Task 17: Adjust the max authentication age setting in the IdM service
- Configure SAML authentication by using the IdM admin console
Task 11: Import the IdP public key into the IdM SAML keystore
In this task, you will export the public key from the ADFS certificate and then import the key into the SAML keystore file of IdM. This task is required for IdM to decrypt SAML responses from ADFS.
Step 1. Export the public key portion of the ADFS federation service certificate
- From your operating system, start Active Directory Federation Services.
- Right-click Federation Service, and then click Properties.
- On the General tab, under Communicating certificate, click View.
- In the Certificate dialog box, select the Details tab.
- On the Details tab, click Copy to File.
- Click Next.
- On the Export Private Key page, make sure that No, do not export the private key is selected, and then click Next.
- On the Export File Format page, select DER encoded binary X.509 (.CER), and then click Next.
-
On the File to Export page, specify the certificate file in File name, and then click Next.
Note In this example, we use Per_ADFS.cer as the file name.
-
Click Finish.
-
Validate success by checking to see that the file you specified was created at the specified location.
Step 2. Import the ADFS public key into the IdM keystore
The IdM SAML keystore file is: <idm-service>\WEB-INF\classes\security\samlKeystore.jks.
To do this, run the following command:
keytool -importcert -alias some-alias -file Per_ADFS.cer -keystore samlKeystore.jks
Note When prompted for the password of samlKeystore.jks, enter nalle123
.
If you want to use your own keystore file instead of the out-of-box one, you need to do the following:
- Replace the out-of-box keystore file with your own one.
-
If your keystore file uses a different name, specify your file in the <idm-service>\WEB-INF\spring\applicationContext.properties file:
idm.saml.keystore=classpath:security/samlKeystore.jks
Replace samlKeystore.jks with your own file name.
-
Specify the following parameters accordingly in the <idm-service>\WEB-INF\spring\applicationContext.properties file:
- idm.saml.keystore.password=ENC(xxx)
- idm.saml.keystore.defaultKey.name=ENC(xxx)
- idm.saml.keystore.defaultKey.password=ENC(xxx)
Note Replace the ENC(xxx) parts with your own values.
After you import the ADFS public key, make sure that you restart your IdM service.