<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.nief.org/index.php?action=history&amp;feed=atom&amp;title=NetIQ_Access_Manager</id>
	<title>NetIQ Access Manager - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.nief.org/index.php?action=history&amp;feed=atom&amp;title=NetIQ_Access_Manager"/>
	<link rel="alternate" type="text/html" href="https://wiki.nief.org/index.php?title=NetIQ_Access_Manager&amp;action=history"/>
	<updated>2026-04-29T15:03:09Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.38.2</generator>
	<entry>
		<id>https://wiki.nief.org/index.php?title=NetIQ_Access_Manager&amp;diff=34&amp;oldid=prev</id>
		<title>Jeff.Krug: Created page with &quot;This page discusses some of the configuration issues with NetIQ Access Manager.  == AuthnContextDeclRef ==  NetIQ Access Manager does not use this field correctly.  In general...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.nief.org/index.php?title=NetIQ_Access_Manager&amp;diff=34&amp;oldid=prev"/>
		<updated>2019-01-22T18:14:20Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;This page discusses some of the configuration issues with NetIQ Access Manager.  == AuthnContextDeclRef ==  NetIQ Access Manager does not use this field correctly.  In general...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;This page discusses some of the configuration issues with NetIQ Access Manager.&lt;br /&gt;
&lt;br /&gt;
== AuthnContextDeclRef ==&lt;br /&gt;
&lt;br /&gt;
NetIQ Access Manager does not use this field correctly.  In general Authn Context Declarations would be used in replace of Authn Context Classes for special interoperability cases.  NetIQ Access Manager uses both Context Classes and includes a Context Declaration Reference.  This is a bit strange as one would presumably supersede the other.  Additionally, a context declaration reference is specifically a URL where the Authentication Context Declaration can be found, but NetIQ Access Manager populates it with just a string by default.  This may have meaning internal to NetIQ Access Manager but it does not have meaning to any other product, and it is not the correct SAML usage.&lt;br /&gt;
&lt;br /&gt;
== Use of SHA-256==&lt;br /&gt;
This page documents some NetIQ settings related to SAML: [[https://www.netiq.com/documentation/netiqaccessmanager4_appliance/identityserverhelp/data/b13ucle3.html NetIQ Docs]].  It includes a property &amp;#039;&amp;#039;&amp;#039;SAML_SIGN_METHODDIGEST_SHA256&amp;#039;&amp;#039;&amp;#039; that can be set to force the device to use SHA256.&lt;br /&gt;
&lt;br /&gt;
== Use of Metadata ==&lt;br /&gt;
Thus far in our testing (2014 Feb 12) NetIQ Access Manager does not seem to be able to import SAML 2 Metadata with much success.  Based on that, here is some guidance on how to extract relevant configuration details for SAML 2.0.&lt;br /&gt;
&lt;br /&gt;
=== Extracting Certificates ===&lt;br /&gt;
Using an text editor, typically one that includes column numbers in some fashion.  You want to open a new file and paste in the following:&lt;br /&gt;
&lt;br /&gt;
  -----BEGIN CERTIFICATE-----&lt;br /&gt;
  -----END CERTIFICATE-----&lt;br /&gt;
&lt;br /&gt;
Then open the metadata file and find the certificate in base64. If you are creating a certificate for a service provider you want to locate the section in the metadata with this tag &amp;#039;&amp;#039;&amp;#039;&amp;lt;SPSSODescriptor ...&amp;gt;&amp;#039;&amp;#039;&amp;#039;.  Then locate the certificate within this section, it will be enclosed within these tags &amp;#039;&amp;#039;&amp;#039;&amp;lt;X509Certificate&amp;gt;&amp;#039;&amp;#039;&amp;#039;.  If there are multiple certificates, you will need to create multiple files and then review them for which is the most appropriate to use.  &lt;br /&gt;
&lt;br /&gt;
Copy the base64 text between the opening tag &amp;#039;&amp;#039;&amp;#039;&amp;lt;X509Certificate&amp;gt;&amp;#039;&amp;#039;&amp;#039; and the closing &amp;#039;&amp;#039;&amp;#039;&amp;lt;/X509Certificate&amp;gt;&amp;#039;&amp;#039;&amp;#039;.  Paste this text in between the two lines above in the certificate file.  &lt;br /&gt;
&lt;br /&gt;
If the file you are copying from included the certificate on a single line, you need to add carriage returns so that each line is 63 characters long (this is why a text editor with column numbers is useful).  The final resulting file should look like this:&lt;br /&gt;
&lt;br /&gt;
  -----BEGIN CERTIFICATE-----&lt;br /&gt;
  MIIF8TCCA9mgAwIBAgIBKjANBgkqhkiG9w0BAQsFADCBqjELMAkGA1UEBhMCVVMx&lt;br /&gt;
  CzAJBgNVBAgTAkdBMRAwDgYDVQQHEwdBdGxhbnRhMQ0wCwYDVQQKEwRHVFJJMRMw&lt;br /&gt;
  EQYDVQQLEwpJQ0wgLSBJRUFEMTkwNwYDVQQDEzBHRklQTSBSZWZlcmVuY2UgRmVk&lt;br /&gt;
  ZXJhdGlvbiBDZXJ0aWZpY2F0ZSBBdXRob3JpdHkxHTAbBgkqhkiG9w0BCQEWDmhl&lt;br /&gt;
  bHBAZ2ZpcG0ubmV0MB4XDTEyMDMxNTE1MzIyNFoXDTE3MDMxNTE1MzIyNFowbzEd&lt;br /&gt;
  MBsGA1UEAxMUcmhlbHNwLnJlZi5nZmlwbS5uZXQxCzAJBgNVBAgTAkdBMQswCQYD&lt;br /&gt;
  VQQGEwJVUzEVMBMGA1UEChMMR2VvcmdpYSBUZWNoMR0wGwYDVQQLExRHVFJJIC0g&lt;br /&gt;
  R0ZJUE0gUHJvamVjdDCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBANHD&lt;br /&gt;
  S+kyIFdINFXFACq8sTn6/v59ngqh76ZKSl+Ad5ICeTbto5P+qAIt5t+5++IhjyL5&lt;br /&gt;
  YYuiQ+IUcZu4nDE++XC3+O7TmTGwxEZ0eHe4mTVbEXzdxJECi9OPbAv+CCHd/O33&lt;br /&gt;
  +95x5+JKLpwUOIbnHQNrXXGkbZlsl9RchQsv2Grbt9JkImTs5b/DjA9wiT2i42Kh&lt;br /&gt;
  CK3J78D+QCkxR+T5TT0CXe4BljZXvEy2TRtQb8M6A8I6Uo249RuFLpGyDr45Mqre&lt;br /&gt;
  3MWplhGUaJ49f/U1fFq38b2gOyDUVua0KyVYuHJ+HIleO2BI26Pz1oweD6Wuyl8J&lt;br /&gt;
  PStTLp9pNChZ9336BFhLYoY32FDlTBqo3PrcJ78dOl04rgaX7E1167YiEAsMcov8&lt;br /&gt;
  Go1IdqFMeE9aN2CbxesKMgdwoP+EOzf0XkErn59L2Dnq1hOPOG/LQwnmJTfrHjqe&lt;br /&gt;
  Bnvv/67L7j7w8lQbiVbgSPT1MrAC0nUNVNOY3JtQHuYWkxkDJaD3ytQuyKUkbPXU&lt;br /&gt;
  d9eilY4INgzVtFSU4fU+IPg0jt3DGqUK2BI7G8nMALXlJEEnNQvUUCyrqKbO5ULg&lt;br /&gt;
  CumyjTeD+ZtFvL1QG2Cm0ZGxoDUhps3bBs/EpmH7tyT2vtdlapV1dl4cXQxdrS+6&lt;br /&gt;
  2gwIflUkEB/PYqjxL5oAtLOon4IeTHAXw0yI/Y0HAgMBAAGjXDBaMAkGA1UdEwQC&lt;br /&gt;
  MAAwEQYJYIZIAYb4QgEBBAQDAgZAMDoGCWCGSAGG+EIBBAQtFitodHRwOi8vcmVm&lt;br /&gt;
  LmdmaXBtLm5ldC9jZXJ0cy9yZWYtZ2ZpcG0tY2EuY3JsMA0GCSqGSIb3DQEBCwUA&lt;br /&gt;
  A4ICAQA4M9QC5UpwJc+k0yglhhi9R9f81MUh+esCY+31lXKDt94tgLci/KXMQLnG&lt;br /&gt;
  fdM3Aee12G6fYv4G1ATotBIHIBevP7LYxTImubBdm2xDuzxgr9rPNwlk32fFwqbc&lt;br /&gt;
  mDDgWm7UmYwOoPAf0va3XeSD86Q6VjXeoaa8uAOItkqmmzSe5qIJfX0qznL44GCI&lt;br /&gt;
  33XLgKwzNZB2TbPb1d3EQohfkcZwQXLHokXIFipSbYPz73v6AFs5S/EcqRT6ldIE&lt;br /&gt;
  DCKJND4Rip0VvmIqI7QUkwMnpcohIiU2kRurUp8zOTrtEf+8tORxDUSjgEVmcvgi&lt;br /&gt;
  rKdt2pnBpYokyLs6wsmPggJL9+/5AEuE23CES3ruZ1aiIBWOpAtCZSAgLK+c8c+Q&lt;br /&gt;
  HCTSuzSaPekiugjaKWmDCe83d7yZQ7dIHYlO/AqYpjWi901NQYPJQGCOP8Ar7hKs&lt;br /&gt;
  oA+2SVOUG+tGa6cIBmWvpNO9xTPfE0y9X9FI/TK3l2/IO7z6IMu5iv7MCXAr6N3G&lt;br /&gt;
  aehxtz96m0wgRAQdlKzRNf4T4KV7092pDe50IDRcOUR43JML18IjE85GW4adMNGn&lt;br /&gt;
  1q6RGRai/Ux0w/SdqcrR7sOWNizIMBMtDd6MMm16aBVfMVdiLDpPl+uV40r6virM&lt;br /&gt;
  TL3JOaisSS3lw8aDc0vVslsm+SjrfPfP0Rwvbtyflm0ZLxGmBw==&lt;br /&gt;
  -----END CERTIFICATE-----&lt;br /&gt;
&lt;br /&gt;
Save the file with a crt or pem file extension.  To insure that errors were introduced when the file was created open the file either by double clicking in Windows or in other operating systems use your Internet browser.  You can review the text contents of the file this way to validate it&amp;#039;s correct.&lt;br /&gt;
&lt;br /&gt;
== Attribute Names ==&lt;br /&gt;
When configuring GFIPM Attributes in NetIQ Access Manager, do not specify a namespace, set the remote attribute name to the full formal name for the GFIPM Attribute, and specify the attribute NameFormat as URI (it seems to default to Unspecified).&lt;/div&gt;</summary>
		<author><name>Jeff.Krug</name></author>
	</entry>
</feed>