Micro Focus Community
Micro Focus Community
  • Site
  • User
  • Site
  • Search
  • User
Micro Focus Community
  • Blogs
  • Ask & Explore
  • Community Guide
  •  

    Menu

    ×
  1. Welcome
  2. Application Delivery Management

      Application Delivery Management

      ×
    1. AccuRev
    2. Agile Manager
    3. ALM / Quality Center
    4. ALM Octane
    5. Business Process Testing
    6. Deployment Automation
    7. Dimensions CM
    8. Dimensions RM
    9. LoadRunner Cloud
    10. LoadRunner Enterprise
    11. LoadRunner Professional
    12. Micro Focus Connect
    13. Model-Based Testing
    14. Project and Portfolio Mgmt.
    15. PVCS Version Manager
    16. Release Control
    17. Requirements Management
    18. Service Virtualization
    19. Silk Central
    20. Silk Performer
    21. Silk Test
    22. StarTeam
    23. UFT Developer
    24. UFT Mobile
    25. UFT One
    26. ValueEdge Platform
  3. Application Modernization & Connectivity

      Application Modernization & Connectivity

      ×
    1. AMC-INTL
    2. ChangeMan SSM
    3. ChangeMan ZMF
    4. COBOL Analyzer
    5. Comparex
    6. Enterprise Analyzer
    7. Enterprise Developer
    8. Enterprise Server
    9. Enterprise Test Server
    10. Extend / AcuCOBOL
    11. Extra!
    12. Host Access for the Cloud
    13. Host Access Mgmt/Security Server
    14. Micro Focus and AWS Partnership
    15. Net Express / Server Express
    16. Network Virtualization
    17. OpenFusion
    18. Orbacus
    19. Orbix
    20. Reflection
    21. RM/COBOL
    22. Rumba
    23. StarTool
    24. Verastream
    25. VisiBroker
    26. Visual COBOL
  4. CyberRes

      CyberRes

      ×
    1. CyberRes User Group
    2. ArcSight
    3. File Analysis Suite
    4. File Dynamics
    5. File Reporter
    6. Fortify
    7. Galaxy
    8. NetIQ Access Manager
    9. NetIQ AD Bridge
    10. NetIQ Advanced Authentication
    11. NetIQ Change Guardian
    12. NetIQ Data Access Governance
    13. NetIQ Directory & Resource Administrator
    14. NetIQ eDirectory
    15. NetIQ Group Policy Administrator
    16. NetIQ Identity Governance
    17. NetIQ Identity Manager
    18. NetIQ LDAP Proxy
    19. NetIQ Privileged Account Manager
    20. NetIQ Risk Service
    21. NetIQ Secure API Manager
    22. NetIQ Secure Configuration Manager
    23. NetIQ SecureLogin
    24. NetIQ Security Solutions for IBM i
    25. NetIQ Self Service Password Reset
    26. NetIQ Validator
    27. SecureData
    28. SecureMail
    29. Sentinel
    30. Structured Data Manager
    31. Voltage
  5. Information Management & Governance

      Information Management & Governance

      ×
    1. Content Manager
    2. ControlPoint
    3. Data Protector
    4. eDiscovery
    5. IDOL
    6. Retain
    7. Storage Manager
    8. VM Explorer
  6. IT Operations Management

      IT Operations Management

      ×
    1. Aegis
    2. AppManager
    3. Asset Management
    4. Client Automation
    5. Data Center Automation
    6. Hybrid Cloud Management
    7. Network Operations Management (NNM and Network Automation)
    8. Operations Bridge
    9. Operations Center
    10. Operations Orchestration
    11. OPTIC (ITOM Platform)
    12. PlateSpin
    13. Robotic Process Automation
    14. Service Management Automation
    15. Service Request Center (SRC)
    16. Service Support Manager (SSM)
    17. SMA-Service Manager Suite
    18. SMAX Suite
    19. Solutions Business Manager
    20. Storage Operations Manager
    21. Universal Discovery & CMDB
  7. Team Collaboration and Endpoint Management

      Team Collaboration and Endpoint Management

      ×
    1. Connected Backup
    2. Filr
    3. GroupWise Products
    4. iPrint
    5. Open Enterprise Server
    6. Vibe
    7. ZENworks
  8. Control Tower
  9. Micro Focus Marketplace
  10. Technical Insights Series
  • User
  • Site
  • Search
  • User
    NetIQ Access Manager
    Community Home › CyberRes › NetIQ Access Management › NetIQ Access Manager › Access Manager Tips & Information

    NetIQ Access Manager

    • Home
    • Discussions
    • Tips & Info
    • Idea Exchange
    • CyberRes Blogs
    • News & Events
    • New
    • Access Manager Tips & Information
    • "Go For Micro Focus If You Are Looking For Access Management Solution", Gartner Peer Insights
    • 2020 Vendors to Know: Privileged Access Management
    • Accepted Solutions - an easy way for community members to locate answers!
    • Access Amazon Web Services using Amazon Cognito for Mobile Applications and NetIQ Access Manager 4.1
    • Access Gateway and SNI support
    • Access management: the keys to the digital kingdom
    • Access Manager - support and training videos on MF YouTube channel
    • Access Manager - Syslog for Auditing on Windows using syslog-ng
    • Access Manager - Syslog for Multi-Target Auditing on Windows using syslog-ng
    • Access Manager 4.0.1, Access Gateway Appliance failed installation
    • Access manager 5 Announcement
    • Access Manager 5 Announcement (2865405)
    • Access Manager Accepted Solutions, version 2 --June 2020
    • Access Manager attribute manipulation - Part 1
    • Access Manager attribute manipulation - Part 2
    • Access Manager Auditing over UDP and TLS
    • Access Manager Docker deployment steps in Microsoft Azure
    • Access Manager IDP Port Redirection Script for RHEL 7.x
    • Access Manager on Public cloud
    • Access Manager Upgrade Test Framework
    • Access Manager: Multiple Published DNS Names for the Same Resource
    • Active directory nested groups with NetIQ Access Manager
    • Adaptive (risk-based) authentication for NetIQ Access Manager
    • Adding a "Forgot My Password" link to the Novell Access Manager login page
    • Adelaide's Insync Solutions deploys Micro Focus identity management for SA Govt project
    • AGS 6: ACF2 Collector and Simulator
    • Ajax /jQuery based NAM authentication
    • Analytics Dashboard as Remote syslog server over TLS
    • Analytics Dashboard(Early Access) Troubleshooting
    • Audit Starter Pack: Installation, Configuration and Usage Instructions
    • Auto Scaling of Access Manager Identity Servers in AWS
    • Automatic hybrid Azure AD join for Windows 10 devices
    • Automatisiertes IAM von Micro Focus liefert entscheidende Vorteile (in German)
    • Azure AD Conditional Access with Access Manager
    • Azure AD Integration with NAM
    • BA Authentication modules for Novell Access Manager 3.1
    • BorderManager Filters Database 2.8
    • +Build Custom Authentication Class for performing Authentication and Authorization together
    • Change log-severity of Access Gateway on the fly
    • Changing Ports in Novell Access Manager 3.0.1
    • Chrome Extension for NAM Desktop Users
    • Chromebook SSO with NAM
    • Cisco CSS L4 switch examples for use with Novell Access Manager 3.1
    • Clearing Novell Access Manager Application Sessions
    • Client Integrity Check (CIC) failing due to version mismatch
    • CloudFormation Template to deploy NetIQ Access Manager in AWS
    • Code Promotion Early Access for NetIQ Access Manager
    • Configure Access Manager to access AWS Management Console using SAML federation and dynamically map LDAP (user store) group to AWS Role - Part 2
    • Configure Access Manager to access AWS Management Console using SAML federation and dynamically map LDAP (user store) group to AWS Role using Virtual Attribute
    • Configure Access Manager to access AWS Management Console with single Role using SAML federation - Part 1
    • Configure Access Manager to Inject Data Using Virtual Attribute
    • Configure Access Manager to Use Custom and Complex Authorization Logic Using Policy Extension
    • Configure Access Manager to Use Custom and Complex Identity Injection Logic Using Data Extension
    • Configure and Activate eDirectory Auditing in Netiq Access Manager Administration Console
    • Configure Instagram with Access Manager for Social Authentication
    • Configure Kubernetes Cluster on Ubuntu and Deploy NetIQ Access Manager Docker images(beta)
    • Configure NAM Identity Server (NetIQ IDP) as a Service Provider
    • Configure NAM to display a "Maintenance Page" rather than displaying the default NAM error page.
    • Configuring Access Manager to send audit events to Sentinel and Analytics Server simultaneously
    • Configuring and Troubleshooting SAML 1.1 with Novell Access Manager
    • Configuring Outlook Web Access 2003 with Single Sign-on using Novell Access Manager
    • Configuring Secure Identity Federation in Novell Access Manager
    • +Configuring Single Sign On (SSO) from NetIQ Access Manager to Novell Service Desk (LiveTime) using SAML
    • Configuring Single Sign On for iFolder 3.6 Server Web Access using Novell Access Manager
    • Configuring SUSE Firewall for the SSL VPN Component in Access Manager
    • Connecting dots to Kubernetes (K8s) resources published for Access Manager
    • Creating Geo Map which provides granular information like city/state in Analytics Dashboard
    • Creating an Access Manager Reverse Proxy for LexisNexis Academic
    • Custom IDP Class to Check the Integrity of the Client Machine
    • Custom SQL Authentication Class for NetIQ Access Manager
    • Customizable B2C Portal for Access Manager
    • Customizing Error Messages in Access Manager Login Pages
    • Customizing Proxy Error Pages in Access Manager
    • CyberRes Engage Newsletter - April 2021
    • Cybersecurity Summit On-Demand: The Path to Universal Policy Management
    • Deploying Azure Kubernetes Cluster and NAM Docker images (beta) using Azure CLI and Terraform
    • Deploying NetIQ Access Manager in AWS for High Availability and Fault Tolerance
    • Deploying Self Service Password Reset (SSPR) with NetIQ Access Manager (NAM)
    • Distributing file changes to IDP cluster nodes
    • Domestic appliance manufacturer tightens security by enhancing control over access rights
    • draft
    • Easily Install/Upgrade/Manage Highly Available Kubernetes Cluster with Kubespray Automation
    • Easy NAM Client
    • EM_CreateGlobalGroupDLs.txt
    • EM_EXT_AddX500Address.txt
    • EM_MbxPost_RemoveX400.txt
    • EM_MbxPost_Remove_targetAddress.txt
    • EM_MbxPost_RetainSourceDN.txt
    • EM_MbxPost_RetrieveTargetSamFromDMA.txt
    • Enable Geolocation in Access Manager Analytics Dashboard
    • Enable the SAP Solution Manager through Novell Access Manager.
    • Enabling MS SharePoint with SSO Through Access Manager - Part 1
    • Enabling SAML2 Federation For Existing Java Web Application
    • Enabling SSO for AGS using NetIQ Access Manager
    • Enforce authentication at Identity Server for the OAuth Client Applications
    • Ensuring Proper Scheduling of Identity Provider and Access Gateway Pods when upgrade is performed for Access Manager docker images deployed on Kubernetes cluster
    • Essay Contest Winner: End-to-End Identity and Access Management
    • Event generation script for Access Manager Analytics Server
    • Exchange SAML 2 Assertion with OAuth Access Token Using NAM 4.4
    • Exchanging Oauth2 Access Token with SAML2 Assertion
    • Exploding Log Files on NAM 4.2
    • False Duplicate Seed for nonexistent nodes
    • Finding Form Fill Secret Store Details in Access Manager
    • Five Reasons Why API Security Needs Access Management
    • Five Tips to Enable Secure Access for Your Remote Workforce
    • Fixing Multiple Interface Problems with Tomcat on Novell Access Manager 3.0.1
    • Forcing NetIQ Access Manager logins to be processed by NetIQ SSPR
    • Forwarding Events from Sentinel or Access Manager Analytics Server to Splunk / ArcSight
    • Gartner IAM Speaking Session: The Road to Autonomous Identity and Access Management, May 12
    • Gartner Identity & Access Management Summit 2021 | Americas | Virtual, May 11-12
    • Gartner Identity & Access Management Summit, May 11 – 12, 2021| Virtual
    • Gartner Says Working from Home is the New Norm – Lessons Learned from the Gartner IAM Summit
    • General understanding of Docker and Kubernetes
    • Handle “Access Gateway Appliance Console” output
    • Health Check Tool
    • Helm (K8s): Basic commands to deploy and manage an application through charts
    • How IAM powers cyber resilience: 5 best practices
    • How to automate the Installation of NetIQ Access Manager using Ansible
    • How to automate the upgrade process of NetIQ Access Manager using Ansible
    • How to Configure NetIQ Access Manager for NTLM Authentication by Extending Existing Kerberos Authentication
    • How To Configure WS-Trust .NET client for NetIQ Access Manager 4.0
    • How to define a whitelist of trusted domains to validate against during a login to Access Manager's Identity Server
    • How to disable the question asking if the user consents to federate with service provider
    • How to do SSO into your Mobile Applications
    • How to forcefully remove an existing authenticated user from the IDP server with this free tool
    • How to get rcnovell-<service> working on RHEL 7.9 and RHEL 8.x
    • How to get single sign-on right in today's hybrid IT environments
    • How to Integrate NetIQ Access Manager with external OAuth Providers
    • How to Integrate NetIQ Access Manager with Google Authenticator for two-factor authentication
    • How to Integrate NetIQ Access Manager with reCaptcha for login form failures without NAM code change
    • How to Integrate NetIQ Access Manager with ServiceNow IT Service Management Software
    • How to Integrate NetIQ Access Manager with Symantec VIP two-factor authentication
    • How to meet privacy requirements with your PII
    • How to modify user LDAP attributes on local authentication with NetIQ Access Manager
    • How to pass users actual address to NAM Identity Server when request coming in via Load Balancer or Proxy server
    • How to single sign on with NetIdentity to Novell Access Manager
    • How to troubleshoot Access Manager Form Fill policies
    • How to troubleshoot NAM claims WS Federation protocol
    • How to troubleshoot NAM SSL Handshake errors with origin web server
    • How to use Kerberos with NAM with multiple, non-trusted AD Domains
    • How VMWare ESX and ESXi Memory Ballooning impacts Access Manager
    • Howto Front End Novell Access Manager with a Citrix Netscaler SSL Terminator
    • Howto get an A rating for Access Manager against SSL Labs
    • Howto: Preventing Access Manager Users From Accessing the Identity Server Portal Page
    • IAM Whitepaper: Zero Trust: Rethinking Security
    • iChain/Access Manager Migration and Logouts
    • Identiteit zorgt voor veiligheid (in Dutch)
    • Identity & Security Management: Time Zone and Daylight Saving Changes
    • Identity Proofing Online with New User Registration using Jumio's Service
    • Integrating Novell Access Manager with Oracle Internet Directory
    • Integrating a .net application with Access Manager using WS-Federation
    • Integrating Access Manager with SharePoint server using WS-Federation and Claims based authent.
    • Integrating Advanced Authentication 5.5 with Access Manager using SAML 2.0 Protocol
    • Integrating Akamai EAA and Access Manager using SAML2
    • Integrating Cisco WebEx and Novell Access Manager 3.1 using SAML2
    • Integrating Google Apps and Novell Access Manager using SAML2
    • Integrating Identity Manager 4.5.4 User Application with Access Manager 4.3 Access Gateway
    • Integrating Novell Access Manager SAML2 Identity Provider with a Shibboleth SAML2 Service Provider
    • Integrating Novell Access Manager with ActivIdentity 4TRESS AAA Server 6.6
    • Integrating Novell's Access Manager with Shibboleth's IDP Server
    • Integrating Salesforce.com and NetIQ Access Manager using SAML2 (UPDATE)
    • IR1 for Novell Access Manager is Available
    • KCD support with Access Manager 5
    • Kerberos Authentication against Multiple Domains
    • Kerberos authentication may fail with Access Manager Identity Server for users with large group memberships
    • Kubernetes (K8s): Examples of Some Basic Kubectl Commands
    • Kubernetes: Switch between namespaces and contexts effortlessness
    • Lens: The Kubernetes IDE for managing Kubernetes (K8s) clusters
    • Leverage Vertica to offer UBA solutions using NetIQ Access Manager
    • Limit Access to Office 365 Based on the Location of Client
    • Limit NAM X.509 Authentication to specific Certificate Authority
    • Log Capturing in Access Manager
    • Log into Access Manager using a web camera.
    • Lotus Notes Redirection on Novell Access Manager Using PHP and LDAP
    • Making Your Organisation Cyber Resilient with Zero Trust
    • Maxmind Geolocation Provider for Risk Based Authentication with NAM 4.1
    • Metadata Lookup In Access Manager
    • Michiel uncovers – Veiligheid, een business issue (video in Dutch)
    • Micro Focus Access Manager – контролиран и защитен достъп до приложенията (in Russian)
    • Micro Focus Access Manager – сигурен достъп до приложенията (Bulgarian)
    • Migrating_Windows_2000.pdf
    • Migration Process Of NAM Components From SLES To RHEL
    • Mitigating “Super Human login” with Risk Based Authentication ( NAM )
    • Monitor NetIQ Access Manager using SNMP with Cacti
    • Monitoring Access Manager with New Relic APM
    • Monitoring NetIQ Access Manager using SNMP with Nagios
    • Myth about TCP Port 443 and Novell Access Manager 3.0 SSLVPN
    • NAM 5.0 : Advanced File Configurator: End of manual Customization(A simple example)
    • NAM and Intune: Device Authentication
    • NAM as OpenID Connect provider for Salesforce
    • NAM IDP User Session – View Session Details or Terminate User Session(s)
    • NAM OAuth: Simple steps to Inject OAuth Claims and Scopes to backend webserver using Access Gateway
    • NAM OAuth: Simple steps to Inject OAuth token to Backend Webserver using Access Gateway
    • NAM Open Lab 3: Configuring Identity Server, LDAP User Store, Device Manager
    • NAM User Attribute Retrieval from REST Endpoint and Transformation into Virtual Attribute
    • NAM-AAF Integration: Use mailcatcher as SMTP server for EmailOTP
    • NAM4, enable multiple SSL certificates for domain based proxy services on the same reverse proxy
    • NAM: Application Hosted Login Page and Passing Session Timeout and Other Login Failed Responses
    • NAMCookieAuth for NetIQ Access Manager v1.0
    • NAM’s Custom IDP Discovery Service Implementation
    • NetIQ Access Manager integration with PAM SSO | SR 101307651501
    • NetIQ Access Manager - Javascript Injection Policies
    • NetIQ Access Manager - Oracle EBS SSO Integration
    • NetIQ Access Manager Education Course Offerings
    • NetIQ Access Manager LDAP Server Plug-in for OID
    • NetIQ Access Manager Real Time Analytics Using AWS Kinesis Service
    • NetIQ Access Manager Solution Pack: Sample Reports
    • NetIQ Access Manager SSO to Office 365
    • NetIQ Access Manager – Adding External Data to SAML Assertions
    • NetIQ Access Manager: Auto Scaling of Identity Server in AWS - Lambda function
    • Netiq Access Manager: Using java functions inside Virtual Attributes for complex modifications
    • NetIQ_CustomizingDMAwithScripting.pdf
    • New Analytics Server in Access Manager 4.3
    • New version of NetIQ Access Review released
    • Non-redirected login at Access Gateway
    • NordicEdge Strong authentication through one time password for Novell Access Manager 3
    • Novell Access Manager - "Detected URL Tampering"
    • Novell Access Manager 3.1 SSL VPN Appliance
    • Novell Access Manager and Zeus ZXTM LB
    • Novell Access Manager SSO using Identity Injection for the Oracle E-Business Suite
    • Novell Audit Starter Pack Database Version 1.3
    • Oauth Consent Management Operations
    • OAuth Resource Owner Flow with additional contract parameter
    • OAuth Scopes\Claims Restriction
    • Oauth2 Mobile Client for NetIQ Access Manager 4.1 using Implicit Flow
    • OAuth2 Reference for Access Manager
    • OAuth2 Service Broker Custom Endpoint
    • On-demand webinar: Five Reasons Why API Security Needs Access Management
    • One Click GroupWise WebAccess
    • Open Lab: Installing Novell Access Manager
    • OpenID Connect with the NAM Identity Server and Oauth2 Playground
    • Part1 - Docker Commands with Examples
    • Part2 - Docker Commands with Examples
    • Password less login using Web Authentication on windows, ios, and android browsers
    • Personalizing Novell Access Manager Using Custom Headers and LDAP
    • Post Processing after NAM Authentication
    • Power-up Access Gateway with ModSecurity and Core Rule Set
    • Preventing Un-validated Redirects on the Access Gateway Service using a Whitelist
    • Principal Consultant Engineer in the Education Industry gives Micro Focus NetIQ Access Manager ★★★★★'s on Gartner Peer Insights
    • Protect Access Manager Admin Console When Installed on the Same Machine as the Identity Server
    • Quick and Easy Load Testing for Novell Access Manager (NAM) 3.x
    • Quick Session Switch Over to Mobile
    • RBA: Block IP Addresses from a URL
    • RBA: Text Based IP Address Block List file for NetIQ Access Manager
    • Real-life Tips on Configuring Kerberos for Authentication in Access Manager
    • Refreshing Metadata using REST API
    • Relationships of Trust: Novell Access Manager: Simplifying Multi-Community Access to SharePoint
    • Repairing Damaged Access Gateway Objects in Access Manager 3.1
    • Retrieve logged in user in UserApp forms
    • SaaS Account Management - Easy steps to Install, Configure, Interation with Access Manager
    • Salesforce Delegated Authentication with Access Manager
    • Salesforce.com SSO and Novell Access Manager using SAML 2
    • SAML 1.1 Integration with Vertex using Novell Access Manager 3.1
    • SAML SSO to AWS (Amazon Web Services) with NetIQ Access Manager - Part 1
    • Scripting NetIQ Access Manager Policy Extensions in Groovy
    • Securing Access Manager Sessions
    • Security Engage Newsletter - December 2019
    • Sessions - OAuth with Access Manager using LetsOAuth
    • Setting Up a Group Membership Check in Access Manager
    • Setting Up XNTPD Time on NetWare 6.5 SP5 Servers
    • Setup Access Manager lab using plain docker
    • SimpleSAMLPHP integration with NetIQ Access Manager Identity Provider using SAML 2.0
    • Simulated data generation for Access Manager Analytics server 5.0 beta
    • Single Sign-on to Novell ZENworks using Novell Access Manager's Form Fill Policy
    • Solve the increased CPU and TIME_WAIT connections in LAG
    • SSL VPN Load Balancing for Access Manager
    • Support extension of Access Manager 4.4.x
    • Support Tip: AAF DynamicAuth stops working after NAM upgrade from 4.5.x to 5.0.1
    • Support Tip: Access Manager Console and IDP servers installed on SLES
    • Support Tip: Access Manager Console and IDP servers installed on SLES fail to run logortate
    • Support Tip: Access Manager log4j2.formatMsfNoLookups CVE-2021-44228 CVE-2021-45046
    • Support Tip: Access Manager services failed to start after a reboot on RHEL 7.9 and SLES15SPS
    • Support Tip: Accessing any protected resource configured on the Access Gateway: Unable to authenticate (404-esp-[Access Gateway Device ID])
    • Support Tip: Adding a new secondary NAM 5.0.1.2 appliance fails to add AG to Cluster
    • Support Tip: Adding Risk-based Policies in IE does not select an Identity Server Cluster.
    • Support Tip: Admin Console error novell-tomcat9-service.service loaded failed
    • Support Tip: After NAM upgrade from 4.5.4 to 5.0.1 OAuth AuthCode requests fail with 404 with response_mode=form_post
    • Support Tip: After upgrading NAM IDP server reports Unable to connect to the Interset Server
    • Support Tip: Command to check the version of Java, tomcat, OpenSSL and Apache
    • Support Tip: Creation of Certificate longer than 2 years with Access Manager 5.0.1
    • Support Tip: CVE-2021-44224 Access Manager
    • Support Tip: CVE-2021-44790 Access Manager
    • Support Tip: CVE-2021-44832 Access Manager
    • Support Tip: Dashboard fails after applying an external signed in Certificate to the AC
    • Support Tip: Device Registration for the Access Manager Console version 5.0.2 fails
    • Support Tip: How to obtain Mirror Credentials
    • Support Tip: IDP Health warning "Unable to connect to the Interset Server" after upgrading to NAM 5.0 SP2
    • Support Tip: IDP server fails to start after upgrading from 4.5.3.1-20 to 5.0
    • Support Tip: iManager does not provide individual "Update" on Access Gateway Appliance nodes
    • Support Tip: iManager fails on access IDP / AG node details with HTTP 400 Bad Request after upgrading to 5.0 SP2
    • Support Tip: Internal Server Error on all proxy services after upgrading to NAM 5.0 SP2
    • Support Tip: Managing log rotation for Access Gateway (AG) on Windows
    • Support Tip: NAM IDP Role policy fails on evaluating Active Directory Primary Group on user
    • Support Tip: NetIQ Access Manager and NetIQ Identity Manager support for Windows Server 2022
    • Support Tip: No license found on the secondary console.
    • Support Tip: OAuth Clients applications failing after upgrade to NAM 5.0.2
    • Support Tip: OAuth userinfo endpoint exception if the userDN has more than than 128 chars
    • Support Tip: package conflicts during SLES15 SP2 to SP3 upgrade with Access Gateway Service 5.0 SP2 installed
    • Support Tip: Time is not synchronized between the different Device Manager datastore servers
    • Support Tip: Using 3rd party Service Provider, logout could not be completed, 300101021
    • Support Tip: WS-Trust Authentication of Username Password Token Failed on RST requests
    • Support Tip: zypper migration upgrading SLES15 SP2 to SLES15 SP3 fails after installing Access Manager 5.x
    • Tech Focus User Group: Identity Modernization--The Path to Achieving Continuous Compliance, April 23
    • Technical Insight Series: Easy OAuth and SAML for Internal Applications with Access Manager and Shibboleth
    • Technical Insights Series: NAM 5.0 Analytics Dashboard Features and Customizations, Recording & Presentation available!
    • Technical Insights Series: NetIQ Access Manager update session, Oct. 20
    • Technical Insights Series: Simplifications in Access Manager 5.0, Recording & Presentation available now!
    • Top marks for Micro Focus Access Manager
    • Troubleshooting 100101043 and 100101044 Errors in Access Manager
    • Troubleshooting Pods in Kubernetes (K8s) with kubectl
    • Tutorial on how to single sign-on to Facebook using NetIQ Access Manager
    • Understanding and debugging Kubernetes (K8s) Probes
    • Update MetaData From File
    • Updated List of Accepted Access Manager Solutions, January 27
    • Use a Virtual Attribute to pass an IP Range List for an Access Manager Authorization Policy
    • Use Risk Based Authentication Method to Enable Role Based Access for SAML Federation
    • Useful Firefox SAML tool for debugging problems
    • User Attribute Transformations in Access Manager 4.2 (Virtual Attributes)
    • Usernameless and passwordless login to web applications on windows, ios, and android browsers
    • Using Access Manager as a Web Reverse Proxy
    • Using Access Manager to single sign-on to Advanced Authentication enrollment service
    • Using Facebook Credentials to Authenticate to Novell Access Manager
    • Using JVisualVM Remotely with NetIQ Access Manager
    • Video: Access Management & Control (in Dutch)
    • Video: Access Manager Advanced File Configurator: Modifying Session Timeout
    • Video: Access Manager, Upgrade Assistant, RHEL, SLES, Upgrade, Registration
    • Video: Data Access Governance (DAG) - Microsoft 365 Permissions and Sharing (File Reporter 4.0)
    • Video: Integrating Access Manager with Itsme
    • Video: SLD Portal Login
    • Video: Using Access Manager Analytics Dashboard
    • Webinar - Enterprise Security Spectrum – The Complete Story with Tech Mahindra" on Zero Trust part 1
    • Webinar 18.3 : télétravail et transformation numérique accélérée : renforcer et simplifier les accès
    • Webinar Sécurité des identités, des accès et des données, 9 juin à 11h (in French)
    • Webinar: A CyberRes Solution that balances accessibility and security, Sept. 28
    • Webinar: Adding Intelligence to Adaptive Access
    • Webinar: Adding Intelligence to Adaptive Access, October 7, 2020
    • Webinar: Authentifizierung neu gedacht: Das Zero Trust-Konzept, 28. Juli (in German)
    • Webinar: Data Access Governance: The Right Place, The Right Access, The Right Time | March 10, 2022 | 2:00pm EST
    • Webinar: Five Reasons Why API Security Needs Access Management, April 15
    • Webinar: HIPAA Safe Harbor Security Standards and Access Management | April 26th
    • Webinar: NetIQ Access Management SaaS - Are you ready?, July 13
    • Webinar: The Road to Autonomous IAM, June 16
    • Webinar: Zero Trust – Don’t Forget the People!, June 11
    • White House updates identity, credential and access management policy - FedScoop
    • Windows Support changes with Access Manager 5
    • WordPress SSO with NetIQ Access Manager
    • WSAuthClass for NetIQ Access Manager v1.0
    • Xen Setup for Access Manager
    • YAML basics in Kubernetes (K8s), examples and debugging
    • Zero Trust in tijden van 5G (in Dutch)
    • Zero trust security: What it is, why it matters

    You are currently reviewing an older revision of this page.

    • History View current version

    Howto Front End Novell Access Manager with a Citrix Netscaler SSL Terminator

    Introduction:



    SSL acceleration is a method of offloading the processor-intensive public key encryption algorithms involved in SSL transactions to a hardware terminator, or accelerator. This may be a separate card that plugs into a PCI slot in a computer that contains one or more co-processors able to handle the SSL processing, or a dedicated (and expensive) hardware device.



    The most computationally expensive part of an SSL session is the stage where the SSL server (the Identity or Proxy server in the case of this document) software is required to decrypt the SSL session key (an asymmetric key) that has been sent to it from the SSL client (usually a web browser). This is known as the SSL handshake. Typically a hardware SSL terminator will offload processing of the SSL handshake while leaving the server software to process the less intense symmetric cryptography of the actual SSL data exchange. As well as handling the handshake, the terminator acts as a proxy handling all SSL operations and leaving the server seeing only unencrypted connections.



    The benefits in terms of performance of the Access Manager server are very high, often resulting in faster performance, and higher throughput.



    Although this document focuses on the Citrix Netscaler SSL terminator rewriter configuration, the Access Manager configuration settings will be the same for any SSL terminator. The SSL terminator administration guide is available at http://support.citrix.com/servlet/KbServlet/download/23213-102-645234/NS-TrafficMgmt-Guide.pdf. The actual setup of the SSL terminator was based on the following example - http://www.citrix.com/site/resources/dynamic/accessAnswers/SharePoint_Deployment_Guide.pdf .




    Environment details:



    In the following setup:




    • The Identity (IDP) server and Linux Access Gateway (LAG) HTTP farm were only accessible via the HTTP VIP as shown in Figure 1 below

    • The IDP and LAG servers communicate with each other via the load balancer and not directly

    • All Access Gateway Servers are Linux, and the IDP servers are on SLES 10 SP2

    • The Netscaler is NS 9.1 build 95.3cl

    • The IDP server has TCP 80 defined as it's base URL so that only standard ports traverse the netscaler. The IDP uses iptables to translate requests destined for TCP 80 to TCP 8080 (add references).









    Figure 1: Network overview


    Click to view.





    Netscalar Configuration Details:



    Although there are GUI methods to do all of this, most of the examples in the Citrix documentation and web site tend to list the CLI solutions. For this reason, we have gone with the CLI options.



    Most of the changes are for the IDP server and NOT the LAG ; the LAG, as shown in section below, is capable of rewriting the references itself.



    The configuration instructions assume that the SSL Offload vservers have been created for the LAGs and the IDP servers. We have used the logical name of "Access Manager Access Gateway" for the LAG vserver, and "Access Manager IDP Server" for the IDPs. Vserver setup details are available from the links referenced in the Introduction.



    To enable all the rewrite functionality needed, do the following:




    1. Tell the Netscaler to rewrite information in the HTTP header to be HTTPS:



      The string used within the quotes is the vserver name of the SSL Offload virtual server. Each Access Manager component set will have different names for these things.



      In the CLI:

      set ssl vserver "Access Manager Access Gateway" -sslRedirect ENABLED -redirectPortRewrite ENABLED
      set ssl vserver "Access Manager IDP Server" -sslRedirect ENABLED -redirectPortRewrite ENABLED



      Enabling SSL Redirect (-sslRedirect) causes the NetScaler system to convert any HTTP 302 redirect responses from backend servers to HTTPS redirects.

    • Create a policy to scan the HTTP data (as opposed to headers) as is passes through the netscaler device and replace references of http:// with https://



      In the CLI:

      add rewrite action httpRewriteAction replace_all "http.res.body(50000)" "\"https://\"" -pattern "http://"
      add rewrite policy HttpToHttpsRewrite "http.res.body(50000).contains(\"http://\")" httpRewriteAction



      The (50000) value references the number of bytes to scan through to replace. This number can be tweaked for the size of the page, 50000 was from the citrix support examples.

    • Bind the policy to the IDP Server VIP



      In the CLI:

      bind lb vserver "Access Manager IDP Server" -policyName HttpToHttpsRewrite -priority 100 -gotoPriorityExpression END -type RESPONSE



      This will rewrite the all IDP generated references of http to the https scheme. An example of this would be the following entry in the default login (login.jsp) page which includes the HTML form with an action tag indicating where the credentials are to be posted. The page itself includes the following:

      <form name="IDPLogin" enctype="application/x-www-form-urlencoded" method="POST" action="<%= (String) request.getAttribute("url") %>" AUTOCOMPLETE="off">



      When the JSP is executed, the following is sent back to the browser by the IDP server:

      <form name="IDPLogin" enctype="application/x-www-form-urlencoded" method="POST" action="http://idp126.lab.novell.com/nidp/idff/sso?sid=4" AUTOCOMPLETE="off">



      With our policy defined above, the action tag will be rewritten to:

      <form name="IDPLogin" enctype="application/x-www-form-urlencoded" method="POST" action="https://idp126.lab.novell.com/nidp/idff/sso?sid=4" AUTOCOMPLETE="off">





    Access Manager Configuration Details:



    With the Netscalar taking care of the rewrites of HTTP to HTTPS on the Identity Server, the only changes required on the Access Manager side are for the Linux Access Gateway proxy servers. There are three particular cases where the LAG must have it's scheme rewritten correctly:




    1. All web pages rendered through the LAG must have their schemes rewritten from HTTP to HTTPS.

      With the complexity of Web pages, many SSL terminators have issues rewriting all references in a web page from HTTP to HTTPS. The LAG must take responsibility for this work.

      By default, the LAG rewriter will not rewrite the scheme if the proxy and back-end Web servers being accelerated talk the same protocol. In our case, all traffic into the proxy will be HTTP and all traffic to the back-end Web servers will also be HTTP – implying that no scheme rewriting will take place. Since the browser expects all links to reference HTTPS schemes, the LAG must be configured to automatically rewrite all HTTP references on Web pages to HTTPS.


    • The Liberty Authentication request generated by the LAG must have the target URL rewritten to HTTPS.

      When a user accesses a LAG protected resource, a corresponding Liberty Authentication request is generated by the ESP and sent to the IDP server via the browser. This authentication request includes multiple attributes, including information about the trusted Liberty SP generating the request, a target URL the user must be redirected to post authentication, and the contract to be executed at the IDP server. The target URL will be embedded in this Authentication request and will reference a HTTP resource. The LAG must be able to rewrite this HTTP request to HTTPS. An example of this is the following, sent by the LAG to the IDP via the browser

      HTTP/1.1 302 Moved Temporarily
      Server: Apache-Coyote/1.1
      Set-Cookie: JSESSIONID=AF5484F1CD4D218C5404A17A0DA86E5A; Path=/nesp; secure
      Location: http://idp126.lab.novell.com/nidp/idff/sso?RequestID=idQgvQqocG6fgFrkeiUG6jlRD.LMk&MajorVersion=1&MinorVersion=2&IssueInstant=2010-05-18T13:53:26Z&ProviderID=https://lag129.lab.novell.com:443/nesp/idff/metadata&RelayState=MA==&consent=urn:liberty:consent:unavailable&ForceAuthn=false&IsPassive=false&NameIDPolicy=onetime&ProtocolProfile=http://projectliberty.org/profiles/brws-art&target=http://lag129.lab.novell.com:443/formfill/phpinfo.phpentRef=u&AuthnContextStatemscell/secure/name/password/uri
      Date: Tue, 18 May 2010 13:53:26 GMT
      Content-Length: 0
      Via: 1.1 lag129.lab.novell.com (Access Gateway 3.1.1-265_eng_600589-7AA324FFCBA4D4ED)



      The target parameter, embedded within the Authentication request references "http://lag129.lab.novell.com:443/formfill/phpinfo.php". This needs to be rewritten to use the https scheme e.g. "https://lag129.lab.novell.com:443/formfill/phpinfo.php"



    • The 'Location' HTTP header in the 302 redirects must have it's scheme rewritten from HTTP to HTTPS

      There are two cases where the LAG sends redirects back to the browser:




      • When a non authenticated user tries to access a protected resource, a series of HTTP redirects are generated by the LAG that will redirect the user to the onboard ESP (see XXX for more details), or to the IDP server requesting the users credentials. Browsers execute on these 302 Redirect status codes and generate corresponding requests to the URL defined in the 'Location' HTTP header. The scheme on the 'Location' header must be HTTPS and not the default HTTP.


    • When the back-end Web server sends a 302 Redirect to the browser, the LAG must interpret the URL and make any rewrites it deems necessary (such as scheme and path based multihomed path injection). Since the proxy and back-end Web server scheme are both HTTP in the setup, the Location header will not be rewritten by default.




    The following two files exist on the LAG to handle the first two cases above (a and b), whereas the SSL terminator will handle the later case. The SSL terminator will handle any 'Location' HTTP header rewrites generated by the Web server or LAG.




    1. Rewriting all HTTP references to HTTPS. In the CLI:

      # touch /tmp/.rewriteAlwaysHTTPS


      If this touch file is enabled, the Linux Access Gateway rewrites all HTTP links to HTTPS before rendering the pages to the browser.



    • Rewriting target URL within Liberty Authentication Request. In the CLI

      # touch /var/novell/.ForceHTTPSSchemeInESPRedirection


      In this case, the original URL accessed by the browser is rewritten with the HTTPS scheme. This ensures that the traffic is sent back to the browser after the authentication contains the right protocol (SSL/TLS).



    • Restart the LAG. In the CLI:

      # /etc/init.d/novell-vmc restart 


      Any time a change is made to a touch file, the VMC services must be restarted on the LAG for the changes to register.



    Resources

    Support
    Documentation
    Training
    CyberRes Academy
    Partner Portal
    Contact us
    Compliance
    Help
    Company
    Privacy Policy
    Terms of Use
    Accessibility
    Anti-Slavery Statement
    Support
    How To Buy
    Careers
    Investor Relations
    Follow Us
    © 2021 Micro Focus
    The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.