IBM webMethods Hybrid Integration

IBM webMethods Hybrid Integration

Join this online group to communicate across IBM product users and experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  SAML authentication for web services

    Posted Wed March 27, 2013 10:59 AM

    I am trying to use Software AG provided SAML authentication policies for implementing WS-Security. Has anyone succesfully used these policies? I have basic questions regarding these policies for which I did not get any information from documentation.

    1. What are the requirements for the security token service (STS) used by these policies? I tried using CXF-STS and JBoss Picketlink STS, but did not have any success. Does SoftwareAG recommend any specific STS implementation?
    2. It seems the out of box policies are supported only by the provider descriptor. How do we implement SAML authentication on the consumer descriptor?
    3. Is there any sample/demo avaialable regarding these?

    #webMethods
    #Integration-Server-and-ESB


  • 2.  RE: SAML authentication for web services

    Posted Wed March 27, 2013 11:30 AM

    Please check these articles if you haven’t and some notes should help.


    #Integration-Server-and-ESB
    #webMethods


  • 3.  RE: SAML authentication for web services

    Posted Wed March 27, 2013 11:44 AM

    Rama, Thanks for the pointers. I am familiar with how to use X.509 and Username token policies. However there isn’t enough information about SAML policy implementation in webMethods. My question was specific to SAML authentication.


    #Integration-Server-and-ESB
    #webMethods


  • 4.  RE: SAML authentication for web services

    Posted Wed March 27, 2013 12:34 PM

    You really mean using SAML tokens for WS-Security?..

    HTH,
    RMG


    #webMethods
    #Integration-Server-and-ESB