Chaining different modules
If a complex certificate chain is needed, you can create a certificate chain by using the Realm Editor on the BMC Atrium SSO Admin Console.
The following topics are provided:
To create an additional module
- In the BMC Atrium SSO Admin Console, select the realm you want to configure and click Edit.
- Click Add.
- Select the type of new module instance.
- Provide the module parameters.
For more information about the parameters, see Realm-Editor. - Click Save.
To edit an additional module
- In the BMC Atrium SSO Admin Console, select the realm you want to configure and click Edit.
- Select the module instance check box.
- Click Edit.
A pop-up window opens, allowing you to configure the module attributes.
To change the criteria for a module
- In the BMC Atrium SSO Admin Console, select the realm you want to configure and click Edit.
- On the Flag option for the module, select new criteria from the list.
The criteria for a module alters the authentication status of the chain. The criteria categories are Required, Requisite, Sufficient, and Optional.- Required—This module must authenticate the user. Regardless of whether authentication passes or fails, processing of the chain continues.
- Requisite—This module must authenticate the user. If authentication fails, processing of the chain stops.
- Sufficient—This module might authenticate the user. If authentication passes, processing of the chain stops; otherwise, processing continues.
- Optional—This module might authenticate the user. Processing continues regardless of whether authentication passes or fails.
If all of the Required and Requisite modules pass before either the end of the chain or the first successful Sufficient module, the overall status is successful. When there are no Required or Requisite modules, at least one Sufficient or Optional module must authenticate the user.
To reorder the modules in a chain
- In the BMC Atrium SSO Admin Console, select the realm that you want to configure and click Edit.
- Select the module instance that you want to move.
- Click Up or Down to change the order in which the module instances are processed.
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*