Symantec IGA

 View Only
  • 1.  IDM - SCIM enpoint - set TLS/SNI

    Posted Oct 26, 2020 08:37 AM
    Edited by Zbynek Kurial Oct 26, 2020 08:42 AM

    Our servers are deployed in Kubernetes containers, more serves are sitting on same IP address and for successful establishing connection between IDM and SCIM endpoint (server in Kubernetes) it is needed to send server identification in Client hello message sent from IDM (which acts client role). This should be ensured by TLS/SNI - here is description - https://en.wikipedia.org/wiki/Server_Name_Indication



    I compared same communication between 1. Web browser and endpoint server and 2. IDM and endpoint server. There is missing server name information in IDM captured communication. You can see it in attached picture.
    So is there any way hot to put server name information into Client Hello message?




    Thanks in advance
    Zbynek


  • 2.  RE: IDM - SCIM enpoint - set TLS/SNI

    Broadcom Employee
    Posted Oct 26, 2020 11:09 AM
    Dynamic connector and you can not specific the server name.  TLS is done on the JCS level, not connector level.  You would be unable to display server name to configure it in your endpoint.

    As this function is not available I recommend you open an "ideation".  Please see the toolbar on this page and click on "ideation" for this requested enhancement.  Thank you.

    ------------------------------
    Best regards,

    Scott Owens
    Sr Support Engineer

    ------------------------------
    And, as always Perhaps there are others in the communities who have experience in doing this and we invite them to comment here also.

    Another option may be to reach out to our partner HCL Technologies to see in what way they can assist further. The Enterprise Studio team of HCL can be reached at enterprisestudio@hcl.com. https://www.hcltech.com/enterprise-studio
    ------------------------------
    ------------------------------