Access Keys:
Skip to content (Access Key - 0)

Dorian


Register Trusted Identity Provider


Dorian: Administrators Guide | Developers Guide | Users Guide | caGrid: Documentation Guides

Overview

To enable users to use their existing credentials to gain access to Web/Grid Services, their organization's identity provider must be added or registered to Dorian as a trusted identity provider.  Before registering an identity provider with Dorian, each organization must implement and operate an Authentication Service for their identity provider. The Authentication Service provides a standard Web/Grid service interface for authenticating with organizational identity providers in a Web/Grid service environment.   This standard interface is very important when it comes to building applications as it allows applications to authenticate users with any identity provider without needing to know the specific on how to interact with each type of identity provider.

Once an organization's Authentication Service is operational, the identity provider for the organization can be added to Dorian as a trusted identity provider.

Adding an Identity Provider Using the GAARDS UI

The GAARDS UI enables Dorian administrators to add or register identity providers with Dorian.   To register an identity provider with Dorian, please complete the following steps:

  1. Launch the GAARDS UI
  2. Log onto the Grid
  3. From the Account Management menu select the Grid Account Management sub menu, then select Trusted Identity Provider(s) this will launch the Trusted Identity Provider(s) Window.
  4. From the Service drop down, select the Dorian you wish to search.
  5. Click the Add button, this will launch the Add Trusted Identity Provider Window.
  6. Select the General tab.
  7. In the Name text box enter the name of the identity provider.
  8. In the Display Name text box enter the display name of the identity provider.
  9. From the User Policy drop down, select the user policy or account policy for the identity provider.
  10. Under Acceptable Authentication Methods, select the check boxes for the authentication methods that are acceptable for the identity provider being added.
  11. Select the Authentication Service tab.
  12. In the Authentication Service URL text box enter the service URL of the organization's Authentication Service.
  13. In the Authentication Service Identity text box enter the service identity of the organization's Authentication Service.
  14. Select the Certificate tab.
  15. Click the Import Certificate button, this will launch a file browser.
  16. Browse to the X.509 certificate (PEM format) which corresponds to the private key that is used to sign the SAML Assertions issued by the identity provide (Authentication Service) being added.
  17. Click the Open button, this should populate the certificate fields in the Certificate tab.
  18. Select the Attributes tab.
  19. In the User Id Attribute Namespace text box enter the namespace that the identity provider uses for the user id attribute in the SAML Assertions it issues.
  20. In the User Id Attribute text box enter the name that the identity provider uses for the user id attribute in the SAML Assertions it issues.
  21. In the First Name Attribute Namespace text box enter the namespace that the identity provider uses for the first name attribute in the SAML Assertions it issues.
  22. In the First Name Attribute text box enter the name that the identity provider uses for the first name attribute in the SAML Assertions it issues.
  23. In the Last Name Attribute Namespace text box enter the namespace that the identity provider uses for the last name attribute in the SAML Assertions it issues.
  24. In the Last Name Attribute text box enter the name that the identity provider uses for the last name attribute in the SAML Assertions it issues.
  25. In the Email Attribute Namespace text box enter the namespace that the identity provider uses for the email attribute in the SAML Assertions it issues.
  26. In the Email Attribute text box enter the name that the identity provider uses for the email attribute in the SAML Assertions it issues.
  27. Click the Add button, this will immediately register the identity provider to Dorian as a trusted identity provider.
Last edited by
Stephen Langella (1188 days ago)
Adaptavist Theme Builder Powered by Atlassian Confluence