.NET Framework Bookmark and Share   
 index > Claims based access platform (CBA), code-named Geneva > Where will "geneva" service reside
 

Where will "geneva" service reside

Hello,

I need help in deciding where the "Geneva" server will reside on the network. We have an intranet of about 1000 computers. AD server is in the intranet.
Our publicly accessibleweb servers reside in a DMZ. We planned"Geneva" to run by itself on a virtual server.

The question is, whether to placeit in the DMZ, and open port 389 for it to be able to access our AD, or,
place "Geneva" inside the intranet, in which case, not sure how a service provider will access it.

Is there a best practices document that outlines this layout?

Thanks in advance,
Sandy
greatbear302

This article explains the whole setup: Geneva, Geneva Proxy, Preimeter/DMZ stuff


http://technet.microsoft.com/en-us/library/dd807100(WS.10).aspx
  • Marked As Answer bygreatbear302 Wednesday, September 16, 2009 8:51 PM
  •  
greatbear302
Given the security requirements of a Geneva server, best practice would be to deploy the Geneva server internally along with the Geneva Proxy in your DMZ to receive client requests and forward them along securely. (Over SSL using a client auth certificate between the proxy and the internal server.

More on deploying the Geneva Proxy in the Geneva Design & Deployment guides, here: http://technet.microsoft.com/en-us/library/dd807036(WS.10).aspx
Laura E. Hunter - Directory Services MVP Identity Architect - Oxford Computer Group ILM2 & Identity Training, Upcoming Dates - http://www.oxfordcomputergroup.com/course-dates.aspx
  • Marked As Answer bygreatbear302 Wednesday, September 02, 2009 4:11 PM
  • Proposed As Answer byTravis Spencer Tuesday, September 01, 2009 4:33 PM
  • Unmarked As Answer bygreatbear302 Friday, September 04, 2009 6:26 PM
  •  
Laura E. Hunter
Thanks Laura. We have the same setup in our environment. The Geneva server sitting in the intranet is reachable through the proxy in DMZ, which forwards requests inside, securely by a VeriSign SSL (not sure about client authentication-I have set "Accept" Client Authentication in IIS7).
The problem is, I can't establish trust! I'm using the Federation Utility CTP on the intranet Geneva server, and nothing happens when I click on Establish Trust. Any ideas?
greatbear302

This article explains the whole setup: Geneva, Geneva Proxy, Preimeter/DMZ stuff


http://technet.microsoft.com/en-us/library/dd807100(WS.10).aspx
  • Marked As Answer bygreatbear302 Wednesday, September 16, 2009 8:51 PM
  •  
greatbear302

You can use google to search for other answers

Custom Search

More Threads

• MSIS7006: The single sign on token is not valid
• Custom ClaimsAuthenticationManager and web services - Thread.CurrentPrincipal not set - fails in Beta 2 or just not implemeted?
• Cardspace in combination with smartcard keyset not found error
• Framework SDK on Windows 7
• How to define a desired life time in the security token request
• Is there any documentation on how to federate Geneva server Beta2 with LiveID?
• At what point will visual basic templates be available for the Geneva Framework?
• Why a security token obtained through WSTrustClient still initiates RST/RSTR sequence when calling the relying party
• Setup Error running 'GenevaServer.amd64.msi'
• moving Managed Information Card issuance web site ?