CA SSO: 12.52.101.640 – Expired user able to login

No comment

Hi,   In 12.52.101.640 version, I could see that siteminder is allowing authentication for the password expired user (but with Response Code/Reason as 1).   While testing the same user in 12.52.105.2113, user is not getting authenticated with the response code 19.   Response Codes:Sm_Api_Reason_PwMustChange = 1Sm_Api_Reason_PwExpired = 19   Could you please let me […]

Mandating users to set up security questions

No comment

We have a requirement to enforce the users to set up security questions when they login for the first time.Can someone assist on outlining the steps for the same. The setup uses CA SSO coupled with Sailpoint as the identity management solution. Source: New feed {pubDate}

CA SSO : R12.52 – Supported Auth Requests (for Affiliate Domain)?

No comment

Hi,   Could you please confirm if ‘POST’ Binding Authentication Request is supported for Affiliate Domain (SAML Service Provider) on R12.52 version. If yes, kindly let me know how to configure the same.     Currently, I am getting the below error message. Reason: UNSUPPORTED_AUTHN_REQUEST_BINDING Request received on POST but POST not enabled.]   Reference: Tech […]

Yubikey integration with CA SSO or CA AA

No comment

Team,   We have a requirement to integrate yubikey based authentication in CA SSO or CA AA. I am aware that CA SSO or CA AA doesn’t provide OOTB integration for the same, therefore i am looking for possible alternatives for integrating yubikey with CA SSO or CA AA.   Any pointers is appreciated.   […]

Transaction response time in Policy Server access log

No comment

Hi,   I’ve been working with SSO/SiteMinder for about 15 years and always wondered why the policy server doesn’t echo the transaction response time into the access log. This would provide an incredibly useful method of pro-active monitoring and debugging. We do have APM deployed in Introscope mode but it gives a very high level […]