federation services implementation
we given task of implementing identity management solution in our organization. new idm. part of our research planning implement microsoft’s federated services. have few questions regarding implementation of adfs. says adfs requires 2 organizations first establish trust through public-private keys. used sign , validate when 1 party transmits message another. can please explain these private-public keys are. can please in demonstrating implementation of federated service through test environment. please give information regarding set of test environment microsoft’ federated services_
you're asking far-reaching question which, if it's pre-sales matter, might 1 best broached tam or reseller. ("how design complete identity management solution?" bit beyond scope of support forum.)
that said, here ad fs links started:
www.microsoft.com/geneva
http://www.microsoft.com/windowsserver2003/r2/identity_management/adfswhitepaper.mspx
http://blogs.technet.com/adfs
http://blogs.technet.com/adfs_documentation/
to specific question certificates - adfs uses pki certificates communicate securely between browsers , servers - web traffic must ssl-encrypted, , each federation server have 1 or more server authentication certificates sign saml tokens used destination server(s) make authorization decisions. if these certificates not chain trusted root, each organization need use cross-certification or other accepted method of creating pki trust across organizational boundary.
laura hunter - directory services mvp identity architect - oxford computer group ilm2 & identity training, upcoming dates - http://www.oxfordcomputergroup.com/course-dates.aspx
that said, here ad fs links started:
www.microsoft.com/geneva
http://www.microsoft.com/windowsserver2003/r2/identity_management/adfswhitepaper.mspx
http://blogs.technet.com/adfs
http://blogs.technet.com/adfs_documentation/
to specific question certificates - adfs uses pki certificates communicate securely between browsers , servers - web traffic must ssl-encrypted, , each federation server have 1 or more server authentication certificates sign saml tokens used destination server(s) make authorization decisions. if these certificates not chain trusted root, each organization need use cross-certification or other accepted method of creating pki trust across organizational boundary.
laura hunter - directory services mvp identity architect - oxford computer group ilm2 & identity training, upcoming dates - http://www.oxfordcomputergroup.com/course-dates.aspx
Windows Server > Directory Services
Comments
Post a Comment