SiteMinder
- The client sends the request containing the SiteMinder session cookie in the HTTP header.
- SiteMinder authentication policy authenticates the request against SiteMinder service provider.
Example Policy
AuthenticationBySiteMinder.policy
<wsp:Policy
<wsp:Policy
xmlns:wsp="http://schemas.xmlsoap.org/ws/2004/09/policy"
xmlns:wssp="http://docs.oasis-open.org/ws-sx/ws-securitypolicy/200702"
xmlns:tpa="http://xsd.tns.tibco.com/governance/policy/action/2009" >
<wsp:All>
<wsp:ExactlyOne>
<tpa:AuthenticationByJaas>
<wssp:SupportingTokens>
<tpa:ExactlyOne>
<tpa:SiteminderToken />
</tpa:ExactlyOne>
</wssp:SupportingTokens>
<tpa:SharedResourceLoginModule ResourceInstance="SiteminderAsp" />
</tpa:AuthenticationByJaas>
</wsp:ExactlyOne>
</wsp:All>
</wsp:Policy>