Enabling SAML Authentication with NetScaler for Web Applications

Enabling SAML Authentication with NetScaler for Web Applications

infasetup DefineDomain Command Options

infasetup DefineDomain Command Options

Use the infasetup defineDomain command to enable SAML authentication when you create a domain.
The following example shows the options to configure a domain to use an identity provider:
infasetup defineDomain -cs "jdbc:informatica:oracle://host:1521;sid=DB2" -dt oracle -dn TestDomain -ad test_admin -pd test_admin -ld $HOME/ISP/1011/source/logs -nn TestNode1 -na host1.company.com -saml true -iu <identity provider URL> -spid Prod_Domain -cst 240 -asca adfscert -std \custom\security\ -stp password -mi 10000 -ma 10200 -rf $HOME/ISP/BIN/nodeoptions.xml
The following table describes the SAML options and arguments:
Option
Description
-EnableSaml
-saml
Required. Set this value to true to enable SAML authentication for supported Informatica web applications within the Informatica domain.
Set this value to false to disable SAML authentication for supported Informatica web applications within the Informatica domain.
-idpUrl
-iu
Required if the -saml option is true. Specify the identity provider URL for the domain. You must specify the complete URL string.
-ServiceProviderId
-spid
Optional. The relying party trust name or the service provider identifier for the domain as defined in the identity provider.
If you specified "Informatica" as the relying party trust name in the identity provider, you do not need to specify a value.
-ClockSkewTolerance
-cst
Optional. The allowed time difference between the identity provider host system clock and the master gateway node's system clock.
The lifetime of SAML tokens issued by the identity provider by is set according to the the identity provider host system clock. The lifetime of a SAML token issued by the identity provider is valid if the start time or end time set in the token is within the specified number seconds of the master gateway node's system clock.
Values must be from 0 to 600 seconds. Default is 120 seconds.
-AssertionSigningCertificateAlias
-asca
Required if the -saml option is true. The alias name specified when importing the identity provider assertion signing certificate into the truststore file used for SAML authentication.
-SamlTrustStoreDir
-std
Optional. The directory containing the custom truststore file required to use SAML authentication on gateway nodes within the domain. Specify the directory only, not the full path to the file.
SAML authentication uses the default Informatica truststore if no truststore is specified.
-SamlTrustStorePassword
-stp
Required if you use a custom truststore. The password for the custom truststore file.
See the
Informatica Command Reference
for instructions on using the infasetup defineDomain command.

0 COMMENTS

We’d like to hear from you!