How does Access Manager perform SSO, desktop SSO, and WAM?
Access Manager enables Web SSO, desktop SSO, and federated SSO (Liberty Alliance), and SAML. You establish SSO in Access Manager by enforcing agent-based or proxy-based policies that match your security requirements evaluated on Access Manager’s server environment and hosted on standard platform components, such as LDAP directories and Web or application servers. Access Manager Policy Agents enforce access policies so that users can log in to only those systems, URLs, or objects they are authorized to access. For example, with Windows Desktop SSO, a Kerberos-based authentication plug-in module for Windows 2000, users who are authenticated with a key distribution center present the Kerberos tokens to Access Manager through the Simple and Protected GSS-API Negotiation Mechanism (SPNEGO) protocol. Those users are then authenticated by Access Manager without having to log in again. To implement Kerberos-based SSO in Access Manager through this authentication module, the client must use SPN