Google Search Appliance Authentication/Authorization for User Manual

Browse online or download User Manual for Software Google Search Appliance Authentication/Authorization for . Google Search Appliance Authentication/Authorization for Enterprise SPI Guide User Manual

  • Download
  • Add to my manuals
  • Print
  • Page
    / 33
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 0
Google Search Appliance
Authentication/Authorization for Enterprise SPI Guide
Google Search Appliance software version 6.8 and later
October 2010
Page view 0
1 2 3 4 5 6 ... 32 33

Summary of Contents

Page 1 - Google Search Appliance

Google Search ApplianceAuthentication/Authorization for Enterprise SPI GuideGoogle Search Appliance software version 6.8 and laterOctober 2010

Page 2 - October 2010

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 10HTTP/1.x 302 Moved TemporarilyServer: Apache-Coyote/1.1Set-Cookie: JS

Page 3 - Contents

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 11The SAMLRequest is first DEFLATE-compressed, then Base 64 encoded, th

Page 4 - Enterprise SPI Guide

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 12After Authentication, the IdP can either use Artifact Binding or POST

Page 5 - Security Manager

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 13GET /security-manager/samlassertionconsumer?SAMLart=emwjzal36b2dfyoc8

Page 6 - Authentication

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 14An artifact must not be reusable. Once an artifact is dereferenced, t

Page 7 - Session Cookie

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 15</samlp:ArtifactResponse></SOAP-ENV:Body></SOAP-ENV:En

Page 8

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 16<form action="https://gsa.yourdomain.com/security-manager/sam

Page 9

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 17With the base64 encoded form of the signed SAML Response:<samlp:Re

Page 10

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 18<ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#en

Page 11

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 19When a user performs a search over access-controlled documents, the u

Page 12 - HTTP Artifact Binding

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 2Google, Inc.1600 Amphitheatre ParkwayMountain View, CA 94043www.google

Page 13

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 20Here are the relevant portions of the SAML schema (see http://www.oas

Page 14

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 21<element name="Subject" type="saml:SubjectType"

Page 15 - HTTP POST Binding

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 22Here are some relevant portions of the SAML schema for the response:&

Page 16

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 23<element name="Assertion" type="saml:AssertionType&

Page 17

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 24Since the URL found in the cache link (the cache URL pointed to by th

Page 18 - Authorization

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 25The following is an example of a possible response from the Policy De

Page 19

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 262. Enter the URL of the service so that the system can access the ser

Page 20

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 27The following is an example of a message the search appliance sends t

Page 21

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 28In return, the search appliance expects to receive one or more SAML R

Page 22

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 29GET</saml:Action></saml:AuthzDecisionStatement></saml:

Page 23

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 3ContentsAuthentication/Authorization for Enterprise SPI Guide ...

Page 24

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 30SPI CallFlow DiagramThe following diagram is the complete call flow f

Page 25

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 31References• GSA Admin Toolkit: Sample SPI for authentication and auth

Page 26

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 32IndexSymbols&SAMLRequest= 9, 11AActiveDirectory 4Apache Axis 5Art

Page 27

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide Index 33Xx.509 certificates 4XML 4, 6XML digital signature 15XML digita

Page 28

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 4Authentication/Authorization for Enterprise SPI GuideThe SAML Authenti

Page 29

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 5• SAML 2.0: An XML-based standard whose primary use case is inter-doma

Page 30 - SPI CallFlow Diagram

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 6AuthenticationPurpose of the Google Search Authentication SPIWhen impl

Page 31 - Troubleshooting

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 7• Depending on the SAML Binding option:Artifact Binding• The Identity

Page 32

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 8Assume no prior search appliance session or SSO cookie has been grante

Page 33 - XML digital signatures 5

Google Search Appliance: Authentication/Authorization for Enterprise SPI Guide 9GET /security-manager/samlauthn? SAMLRequest=fZJNT8MwDEDvSPyHKPeuHxIMR

Comments to this Manuals

No comments