Version Affected: All
Overview
Some WS-Federation (WSFed) applications need to read the IdP's metadata, including details such as the supported claims -- but the standard metadata exported from the Admin Console does not include this. This article covers how to enable extended WSFed metadata.
Enable WS-Trust Endpoints
- Open the Admin Console and go to the WS-Fed realm's Post Authentication tab.
- Scroll down to WS-Trust Endpoint Configuration and click View and Configure WS-Trust Endpoints.
- Enable the first two endpoints: /2005/usernamemixed and /2005/windowstransport.
- Click Save.
- Access the metadata using a URL such as:
https://awood05vm.example.local/SecureAuth28/FederationMetadata/2007-06/FederationMetadata.xml
(Replace the server name and realm number with your own.)
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.