Title: How to set up SSL between CA SiteMinder Web Access Manager - SiteMinder Policy Server and Active Directory (AD)



Similar documents
CA SiteMinder. Directory Configuration - OpenLDAP. r6.0 SP6

LDAP over SSL Page 1 of 6.

How To Enable A Websphere To Communicate With Ssl On An Ipad From Aaya One X Portal On A Pc Or Macbook Or Ipad (For Acedo) On A Network With A Password Protected (

Certificate technology on Pulse Secure Access

Certificate technology on Junos Pulse Secure Access

Symantec Managed PKI. Integration Guide for ActiveSync

WebLogic Server 6.1: How to configure SSL for PeopleSoft Application

Setting Up SSL on IIS6 for MEGA Advisor

Outlook Web Access Guide to Installing Root Certificates, Generating CSR and Installing SSL Certificate

Microsoft Dynamics CRM Server 2011 software requirements

DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication

Configuring User Identification via Active Directory

Wavecrest Certificate

Steps to configure SiteMinder Policy Server to connect to CA Directory using LDAPS

Entrust Managed Services PKI. Configuring secure LDAP with Domain Controller digital certificates

SETUP SSL IN SHAREPOINT 2013 (USING SELF-SIGNED CERTIFICATE)

TIBCO Spotfire Platform IT Brief

prefer to maintain their own Certification Authority (CA) system simply because they don t trust an external organization to

Junio SSL WebLogic Oracle. Guía de Instalación. Junio, SSL WebLogic Oracle Guía de Instalación CONFIDENCIAL Página 1 de 19

The IVE also supports using the following additional features with CA certificates:

DMZ Server monitoring with

How to Configure a Secure Connection to Microsoft SQL Server

WHITE PAPER Citrix Secure Gateway Startup Guide

BEA Weblogic Guide to Installing Root Certificates, Generating CSR and Installing SSL Certificate

Certificate Management

etoken Enterprise For: SSL SSL with etoken

Use Enterprise SSO as the Credential Server for Protected Sites

App Orchestration 2.5

HOTPin Integration Guide: Google Apps with Active Directory Federated Services

S/MIME on Good for Enterprise MS Online Certificate Status Protocol. Installation and Configuration Notes. Updated: October 08, 2014

SolarWinds Technical Reference

ECA IIS Instructions. January 2005

SQL Server 2008 and SSL Secure Connection

NSi Mobile Installation Guide. Version 6.2

Step-by-step installation guide for monitoring untrusted servers using Operations Manager (Part 1 of 3)

Entrust Managed Services PKI

Exostar LDAP Proxy / Secure Setup Guide. This document provides information on the following topics:

Certificate Management

Application Note. ShoreTel 9: Active Directory Integration. Integration checklist. AN June 2009

SSL Interception on Proxy SG

User-ID Configuration

Using etoken for Securing s Using Outlook and Outlook Express

Verify LDAP over SSL/TLS (LDAPS) and CA Certificate Using Ldp.exe

White Paper. Installation and Configuration of Fabasoft Folio IMAP Service. Fabasoft Folio 2015 Update Rollup 3

Subversion Server for Windows

Client Authenticated SSL Server Setup Guide for Microsoft Windows IIS

Installation Guide. SafeNet Authentication Service

Configuring Microsoft Active Directory for Oracle Net Naming. An Oracle White Paper April 2014

Upgrading User-ID. Tech Note PAN-OS , Palo Alto Networks, Inc.

Using CertAgent to Obtain Domain Controller and Smart Card Logon Certificates for Active Directory Authentication

Certificate Request Generation and Certificate Installation Instructions for IIS 5 April 14, 2006

Exchange 2010 PKI Configuration Guide

Authentication Methods

Smart Policy - Web Collector. Version 1.1

CHAPTER 7 SSL CONFIGURATION AND TESTING

Microsoft OCS with IPC-R: SIP (M)TLS Trunking. directpacket Product Supplement

CA Nimsoft Service Desk

Customer Tips. Xerox Network Scanning HTTP/HTTPS Configuration using Microsoft IIS. for the user. Purpose. Background

CERTIFICATE-BASED SINGLE SIGN-ON FOR EMC MY DOCUMENTUM FOR MICROSOFT OUTLOOK USING CA SITEMINDER

Digipass Plug-In for IAS. IAS Plug-In IAS. Microsoft's Internet Authentication Service. Installation Guide

ADFS Integration Guidelines

Skyward LDAP Launch Kit Table of Contents

Basic Configuration. Key Operator Tools older products. Program/Change LDAP Server (page 3 of keyop tools) Use LDAP Server must be ON to work

HTTP communication between Symantec Enterprise Vault and Clearwell E- Discovery

Configuring ADFS 3.0 to Communicate with WhosOnLocation SAML

Siteminder Integration Guide

App Orchestration 2.5

Steps to import MCS SSL certificates on a Sametime Server. Securing LDAP connections to and from Sametime server using SSL

How to Order and Install Odette Certificates. Odette CA Help File and User Manual

Enabling SSL and Client Certificates on the SAP J2EE Engine

Sophos Mobile Control Installation guide. Product version: 3.5

Sophos Mobile Control Installation guide. Product version: 3

How to Order and Install Odette Certificates. Odette CA Help File and User Manual

Configuring Microsoft Active Directory 2003 for Net Naming. An Oracle White Paper September 2008

Authentication in XenMobile 8.6 with a Focus on Client Certificate Authentication

WirelessOffice Administrator LDAP/Active Directory Support

Step-by-step installation guide for monitoring untrusted servers using Operations Manager ( Part 3 of 3)

e-cert (Server) User Guide For Microsoft IIS 7.0

Configuring Sponsor Authentication

Using LDAP Authentication in a PowerCenter Domain

External Authentication with Citrix Secure Gateway - Presentation server Authenticating Users Using SecurAccess Server by SecurEnvoy

Configuring a Windows 2003 Server for IAS

Step-by-step Guide for Configuring Cisco ACS server as the Radius with an External Windows Database

HELP DOCUMENTATION E-SSOM DEPLOYMENT GUIDE

Configuring Color Access on the WorkCentre 7120 Using Microsoft Active Directory Customer Tip

Installation Guide. . All right reserved. For more information about Specops Inventory and other Specops products, visit

How to: Install an SSL certificate

This section includes troubleshooting topics about certificates.

HTTP Server Setup for McAfee Endpoint Encryption (Formerly SafeBoot) Table of Contents

App Orchestration 2.0

Configuring idrac6 for Directory Services

Windows Intune Walkthrough: Windows Phone 8 Management

Tenrox. Single Sign-On (SSO) Setup Guide. January, Tenrox. All rights reserved.

IDENTIKEY Server Windows Installation Guide 3.1

Security Assertion Markup Language (SAML) Site Manager Setup

Owner of the content within this article is Written by Marc Grote

Copyright

O Reilly Media, Inc. 3/2/2007

User Documentation for SmartPolicy. Version 1.2

Transcription:

Tech Document Title: How to set up SSL between CA SiteMinder Web Access Manager - SiteMinder Policy Server and Active Directory (AD) Description: The document describes how to setup an encrypted communication channel between the CA SiteMinder Web Access Manager - Policy Server and the Domain Controller hosting the Active Directory (AD) to be integrated as User Data Store. The SiteMinder policy server can be configure to communication to the backend systems two different ways: 1. LDAP namespace (SUN LDAP SDK v5.0.8) 2. AD namespace (Microsoft SDK for communications) A. LDAP namespace: SiteMinder requires the certificate to be in a Netscape version file format (cert7.db), do not use Microsoft Internet Explorer to install the certificate. Two methods: 1) A Old Netscape 4.7 browser to update cert7.db: a) SiteMinder Policy Server requires that the Root CA cert for the Issuer that signed the LDAP server cert, in this case AD, be added to a cert7.db file which it reads to trust the LDAPS connection coming from the LDAP server. b) Get the Root CA cert from the issuer. From the AD machine, grab the file in C:\ called "machine.mycompany.com_machine.mycompany.com.crt" c) Using a Netscape 4. 7 browser add the Root CA cert to its trusted list of Certificate Authorities. This is typically done by using the option to open a file in the Netscape browser. When you open the Root CA cert file you should be asked to place it in its Root CA database. When you are done validate that it did get put into the Root CA list. d) Next close the browser and locate the cert7.db and key3.db pair that the Netscape Browser uses, it should have a recent Timestamp. e) Copy the cert7.db and key3.db file pair to the SiteMinder Policy Server. In SiteMinder's SM Console locate the >>> "Netscape Certificate Database file option and reference the cert7.db file and be sure the key3.db file is in the same directory. f) You should now be able to connect over LDAPS for both User Directories and Policy Stores. 2) Download nss-3.3.2 and use it to update cert7.db - Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. NSS is available under the Mozilla Public License, the GNU General Public License: http://www.mozilla.org/projects/security/pki/nss/ a) Example of usage: Add/List certificates in the database (cert7.db) Add nss bin and lib to the environment path D:\nss-3.3.2\bin;D:\nss-3.3.2\lib Navigate to the cert7.db Example: D:\nss-3.3.2\cert-databases> To add a certificate to the database (cert7.db) get the PEM cert first then run D:\nss-3.3.2\cert-databases\certutil -A -n ps2-root-ca -t "C,C,C" -i CAcert.pem -d. List all certificate in the cert7.db: certutil -L -d. Certificate Name ps2-root-ca Trust Attributes C,C,C c Valid CA C Trusted CA to certs(only server certs for ssl) (implies c)

B. AD namespace: The advantages of using the AD namespace when configuring an Active Directory user store include: SSL connectivity using a native Windows certificate database. Note: Both the Policy Server and the systems hosting Active Directory user stores must have an established trust. For information about configuring Windows systems and Active Directory for SSL, see your Windows documentation. Support for native Windows SASL which allows for secure LDAP bind operations. Support for native Windows SASL which allows for secure LDAP bind operations. The disadvantages include: No support for enhanced LDAP referrals. No support for LDAP paging and sorting operations When authenticating against an AD namespace, the Policy Server binds to Active Directory using SASL. If a user's common name (CN) is different from the user's Windows logon name, the user can still authenticate even if the EnableSaslBind registry setting exists on the Policy Server machine. The EnableSaslBind setting is a DWORD registry key that you can set to 0 or 1: HKLM\Software\Netegrity\SiteMinder\CurrentVersion\Ds\LDAPProvider\EnableSaslBind This setting disables or enables the SASL protocol while authenticating users. For example, if EnableSaslBind does not exist and you configure this setting to 1, the bind occurs with SASL. If EnableSaslBind exists and you configure this setting to 0, the bind occurs with Simple Authentication mechanism. Using Microsoft Certificate Server 1. Download the CA Root Certificate Download the MS root cert from the certificate server's web server URL, e.g. https://fqdn/certsrv Click Download a CA certificate, certificate chain or CRL

Select DER and then click Download CA certificate. Then save the CA in a temp directory and keep the default name certnew.cer. Import certnew.cer into the Policy servers Trusted Root Certification Authorities Start Run MMC (starts Microsoft s Management Console) File Add/Remove Snap-in Add Select Certificates Check Computer account Local Open/Navigate to Certificates under Trusted Root Certification Authorities Right click Certificates All Tasks Import Navigate/select the saved certnew.cer, use default options to import

2. Configure the SSL user store in the Admin UI as described in the documentation for AD Namespace Important: 1. For Enhance Active Directory Integration and SiteMinder password services to function properly you MUST define in the LDAP Search root as the base of the Active directory/defaultnamingcontext (example: dc=ps,dc=com)

2. If a user's common name (CN) is different from the user's Windows logon name, the user can still authenticate, but if you run in Authenticated User s Security Context you may see the following message in the smps.log. Info message: NetBIOS and UPN are not fetched. If the Policy Server is on Windows with AD as user directory the IIS Authentication may fail