Customize the SSO Cookie Attributes

About this task

To implement single sign-on, you use single sign-on attributes. When you configure the basic scenario, you use default attributes. You can customize these settings, including the name of the cookie containing the SSO token, HTTP header associated with a user ID, and the attributes associated with a token. Tokens can be generated with Sterling External Authentication Server or with a third-party application. This procedure assumes you are using Sterling External Authentication Server. Refer to Allow a Third-Party Provider to Create Tokens for instructions on configuring an external application to generate tokens.

Before you customize this page, gather the following information:

  • Provide a value for each Secure Proxy feature listed. Fields listed in the worksheet are required.
  • Accept default values for fields not listed.
  • Note the Configuration Manager field where you will specify the value.

Configuration Manager Field

Feature

Value

Name

Name to assign to the single sign-on configuration.

Front End SSO Token Cookie Name (Inbound)

Name to assign the cookies associated with each token. This value must match the definition in Sterling File Gateway.

Back End SSO User Header Name (Outbound)

The HTTP header name containing the user name that is sent to Sterling File Gateway.

Back End SSO Token Cookie Name (Outbound)

Name to assign the cookies associated with each token. This value must match the definition in Sterling File Gateway.

Procedure

  1. From IBM Sterling Secure Proxy, select Advanced from the left hand-side navigation panel.
  2. Select SSO Configurations to display SSO Configurations page.
  3. To create a new SSO configuration:
    1. Click Add new + to display SSO Configuration page.
    2. Type an SSO configuration name in the Name field.
  4. To edit an existing SSO configuration:
    1. From the navigation menu, click SSO Configurations.
    2. Select the configuration to modify and click Edit icon.
  5. To customize the front-end definitions, click Logon Portal tab and edit the SSO Token Cookie Name field under the Front End section.
  6. To customize the back-end definitions, edit the following fields:
    • Back End SSO User Header Name
    • Back End SSO Token Cookie Name
    Note: The values defined in the back-end fields must match these settings on the Sterling File Gateway and Sterling B2B Integrator system:
    ## HTTP header containing the SSO user 
    security.SSO_USER_HEADER=SM_USER 
    ## SEAS-SSO Configuration 
    ## HTTP cookie containing the SSO token 
    seas-sso.SSO_TOKEN_COOKI

    Refer to the Sterling File Gateway documentation for instructions.

  7. Click Save.