Table of Contents

Search

  1. About the Security Guide
  2. Introduction to Informatica Security
  3. User Authentication
  4. LDAP Authentication
  5. Kerberos Authentication
  6. SAML Authentication for Informatica Web Applications
  7. Domain Security
  8. Security Management in Informatica Administrator
  9. Users and Groups
  10. Privileges and Roles
  11. Permissions
  12. Audit Reports
  13. Appendix A: Command Line Privileges and Permissions
  14. Appendix B: Custom Roles

Security Guide

Security Guide

Configure an Informatica Web Application

Configure an Informatica Web Application

Use the Administrator tool to configure an Informatica Web application to use a SAML identity provider.
  1. In the Administrator tool, click the
    Services and Nodes
    tab.
  2. Select the application or the application service in the Domain Navigator.
    • To configure the Analyst tool application to use an identity provider, select the Analyst Service, and then click the
      Processes
      tab.
    • To configure the Mass Ingestion tool application to use an identity provider, select the Mass Ingestion Service, and then click the
      Processes
      tab.
    • To configure the Metadata Manager application to use an identity provider, select the Metadata Manager Service, and then click the
      Properties
      tab.
    • To configure the Enterprise Data Catalog application or the Catalog Administrator application to use an identity provider, select the Catalog Service, and then click the
      Processes
      tab.
    • To configure the Enterprise Data Preparation application to use an identity provider, select the Enterprise Data Preparation Service, and then click the
      Processes
      tab.
  3. Click the edit icon next to
    SAML Configuration
    .
  4. Enter the properties required to enable the web application to use an identity provider.
    The following table describes the properties you enter:
    Property
    Description
    Identity Provider URL
    Optional. The URL for the identity provider server. You must specify the complete URL string.
    Service Provider ID
    Optional. The relying party trust name or the service provider identifier for the domain as defined in the identity provider.
    Assertion Signing Certificate Alias
    Optional. The alias name specified when importing the identity provider assertion signing certificate into the truststore file used for SAML authentication.
    If you change the alias name, import the corresponding certificate into the truststore file on each gateway node, and then restart the node.
    Clock Skew Tolerance
    Optional. The allowed time difference between the identity provider host system clock and the system clock on the master gateway node.
    Optional. The lifetime of SAML tokens issued by the identity provider by is set according to the identity provider host system clock. The lifetime of a SAML token issued by the identity provider is valid if the start time or end time set in the token is within the specified number seconds of the system clock on the master gateway node.
    Values must be from 0 to 600 seconds. Default is 120 seconds.
    The following image shows the configuration to enable Enterprise Data Catalog to use PingFederate as the identity provider:
  5. Click
    OK
    .
  6. Restart the application or application service after you configure an application to use a SAML identity provider.

0 COMMENTS

We’d like to hear from you!