2.8.9 Configuring an Authentication Response for a Service Provider

Liberty and SAML 2.0 protocols support slightly different options for configuring how you want Identity Server to respond to an authentication request from a service provider. SAML 1.1 does not support sending an authentication request. However, you can configure an Intersite Transfer Service (see Using the Intersite Transfer Service) to trigger a response from Identity Server.

When Identity Server receives an authentication request from a trusted service provider, the request contains the conditions that Identity Server needs to fulfill. You can configure how you want Identity Server to fulfill the binding and name identifier conditions of the request, or for SAML 1.1, respond to the Intersite Transfer Service. For configuration information, refer to one of the following:

You can specify which contract to be used when the authentication request specifies a class or type rather than a contract. For more information, see Specifying Authentication Defaults.

When the service provider sends an authentication request that specifies a specific contract, ensure that Identity Server has a the contract matches the expected URI. For information about how to configure such a contract, see Creating a Contract for a Specific Authentication Type.