SECURING


Setting up a Relying Party Trust for the ID vault server

Set up a Relying Part Trust in Active Directory Federated Services (ADFS) for the Domino ID vault server. These procedures describe steps for ADFS 3.0 and ADFS 4.0.

About this task

This procedure applies to Active Directory Federation Services (ADFS). If you use Tivoli Federated Identity Manager (TFIM), you set up a partnership. For more information, see the article https://www-10.lotus.com/ldd/dominowiki.nsf/dx/Cookbookcol_Setting_up_a_new_partner_on_TFIM?OpenDocument&sa=true in the Notes and Domino wiki.

Procedure

1. From ADFS, select Start -> Administrative Tools -> AD FS Management.

2. Navigate to the Relying Party Trusts folder.

3. Select Action -> Add Relying Party Trust.

4. Click Start to run the Add Relying Party Trustwizard.

5. In the Select Data Source window select Import data about the relying party from a file, select the idp.xml file that you exported from the corresponding ID vault server IdP configuration document. Then, click Next.


6. In the Select Display Name window, enter a Display name to represent the service provider, for example, Domino Renovations Vault. ClickNext.

7. In the Choose Profile window, select AD FS profile and clickNext.

8. In the Configure Certificate window, click Next.

9. In the Configure URL window, select Enable support for the SAML 2.0 WebSSO protocol. For Relying party SAML 2.0 SSO service URL, enter the following URL:


10. In the Configure Identifiers window, in the Relying party trust identifier field, enter a URL to identify the ID vault server, then clickAdd and Next.
11. Click Next to skip the Configure Multi-factor Authentication Now? window.

12. In the Choose Issuance Authorization Rules window, select Permit all users to access this relying party and click Next.

13. In the Ready to Add Trust window, click Next.

14. In the Finish window, select Open the Edit Claim Rules dialog for this replying party trust when the wizard closes and click Close.

15. If the Edit Claim Rules dialog does not open when the wizard closes, right-click the name of the Relying Party Trust that you created, and select Edit Claim Rules...

16. In the Edit Claim Rules dialog, click Add Rule.

17. In the Select Rule Template dialog, for Choose Rule Type, select Send LDAP Attributes as Claims, and click Next.

18. Complete the Configure Rule dialog box:


19. In the Edit Claim Rules dialog, click Apply andOK.

20. In the AD FS Trust Relationships -> Relying Party Trusts folder:


Parent topic: Configuring ID vault servers for federated SAML login
Previous topic: Exporting the ID vault server configuration to an .xml file
Next topic: Configuring the ID vault for federated login