Hi Jarrett,
What you're looking for here, I think, is a way to trigger an SSO event (rather than local authentication) whenever your local Access Manager policy says that an authenticated session is required.
There's really 2 ways to do this:
- Modify the login.html of your WebSEAL server so that it does a client-side-script redirect to trigger SAML authentication. This redirect could be to the local ISAM Federation trigger URL (for SP-initiated SSO) or directly to the trigger URL for the Identity Provider (for IdP-initiated SSSO).
- Create a custom obligation in AAC which is mapped to the trigger URL (either IdP or SP as above). Then create a Context-based Access Policy which returns the obligation to trigger SSO.
Unless you're using AAC anyway, (1) is the easiest to set up.
Cheers... Jon.
------------------------------
Jon Harry
Consulting IT Security Specialist
IBM
------------------------------