pp108 : Creating a Trust Relation (Deprecated)

Creating a Trust Relation (Deprecated)

This topic describes the procedure for creating a trust relation.

Before you begin this task: The certificate that you want to add to a collection of service groups must be first configured in the trust store. Refer to Adding a Certificate to a Trust Store for more information on adding a certificate to the trust store. You must have the role of Security Administrator to create a trust relation.

All service groups that trust a certificate are grouped together to form a trust relation. Service groups that form a trust relation can exchange signed SAML assertions.

  1. On CUSP > My Applications, click (Security Administration). The Security Administration window appears.
  2. Click the Service Group Trust tab. All service groups belonging to a trust relation are displayed in a column. A description for the collection of service groups is displayed on top of the column. The description is for the user's reference alone with no functional significance and hence is optional. All certificates associated with the collection of service group are displayed below the description.
  3. Click to add a group. The Service Group Trust tab space splits to accommodate a blank group beside the existing group.
  4. Double-click the header to describe the trust relation. This description is for the user's reference alone and hence is optional.
  5. Right-click the header and click Set Default to configure this trust relation as the default group, else skip this step.
    Note: All newly created service containers are placed in the default trust relation.
  6. Right-click the certificate section of the trust relation and click Add Certificate. A list of certificates appears in the shortcut menu.
  7. Click a certificate from the list to add it.
  8. Type an alias for the certificate.
  9. Drag the required service groups to the new column, from other collections of service groups.
  10. Click to save the changes.
    A new trust relation is created.
    • At any point during the configuration, click to revert changes to the last saved state.
    • Before deleting the trust relation ensure that the group does not contain any service groups and certificates. The default trust relation cannot be deleted. Right-click the header of the group you want to delete and click Delete Group. Click to save.

Related concepts

Trust Store
Trust Relation