How To: Enable Extended WS-Federation Metadata

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All

     

    Overview

    Some WS-Federation (WSFed) applications need to read the IdP's metadata, including details such as the supported claims -- but the standard metadata exported from the Admin Console does not include this. This article covers how to enable extended WSFed metadata.

     

    Enable WS-Trust Endpoints

    1. Open the Admin Console and go to the WS-Fed realm's Post Authentication tab.
    2. Scroll down to WS-Trust Endpoint Configuration and click View and Configure WS-Trust Endpoints.

    WS-Trust Endpoint Configuration section with the View and Configure WS-Trust endpoints link.

    1. Enable the first two endpoints: /2005/usernamemixed and /2005/windowstransport.

    WS-Trust Endpoint Configuration table with /2005/usernamemixed and /2005/windowstransport checked as enabled.

    1. Click Save.
    2. Access the metadata using a URL such as:

    https://awood05vm.example.local/SecureAuth28/FederationMetadata/2007-06/FederationMetadata.xml

    (Replace the server name and realm number with your own.)


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.