72-61
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter72 Configuring Clientless SSL VPN
SSO Servers
Maximum Retries—Display only. Displays the number of times the ASA retries a failed SSO
authentication attempt. The range is 1 to 5 retries, and the default number of retries is 3.
Request Timeout (seconds)—Display only. Displays the number of seconds before a failed SSO
authentication attempt times out. The range is 1 to 30 seconds, and the default number of seconds is
5.
Add/Edit—Opens the Add/Edit SSO Server dialog box.
Delete—Deletes the selected SSO server.
Assign—Highlight an SSO server and click this button to assign the selected server to one or more
VPN group policies or user policies.
Step1 Configure the SAML server parameters to represent the asserting party (the ASA):
Recipient consumer (Web Agent) URL (same as the assertion consumer URL configured on the
ASA)
Issuer ID, a string, usually the hostname of appliance
Profile type -Browser Post Profile
Step2 Configure certificates.
Step3 Specify that asserting party assertions must be signed.
Step4 Select how the SAML server identifies the user:
Subject Name Type is DN
Subject Name format is uid=<user>
Adding the Cisco Authentication Scheme to SiteMinder
Besides configuring the ASA for SSO with SiteMinder, you must also configure your CA SiteMinder
Policy Server with the Cisco authentication scheme, provided as a Java plug-in. This section presents
general tasks, not a complete procedure. Refer to the CA SiteMinder documentation for the complete
procedure for adding a custom authentication scheme. To configure the Cisco authentication scheme on
your SiteMinder Policy Server, perform the following steps:
Prerequisites
Configuring the SiteMinder Policy Server requires experience with SiteMinder.
Detailed Steps
Step1 With the Siteminder Administration utility, create a custom authentication scheme being sure to use the
following specific arguments:
In the Library field, enter smjavaapi.
In the Secret field, enter the same secret configured in the Secret Key field of the Add SSO Server
dialog to follow.
In the Parameter field, enter CiscoAuthApi.