Inter-site SSO fails on Internet Explorer (IE) 7
Originally Published: 2008-04-24
Article Number
Applies To
Inter-Site Single Sign-On (ISSO)
Access Manager 4.7 agent
Issue
Two domains are configured, A and B for Inter-Site Single Sign-On (ISSO), where domain A act as an ISSO master and B as an slave. When a user tries to access a resource on master Domain A after successfully authentication on Domain B the user is re-prompted to authenticate.
Cause
Internet Explorer 7 blocks the third party cookies with no privacy policy.
Resolution
Here are the steps to make it work.
1) Access domain B first and authenticate as usual.
2) You could see a small spy eye icon at the bottom of the IE browser which appears if it blocks any cookies for a site.
3) Double click on it to see the privacy report. It shows that it is blocking the ClearTrust cookie from domaina.com. At the bottom there is an option to change it to allow cookies from this site. Select this option.
4) Repeat the ISSO use case from slave to master now. It should now work correctly.
Related Articles
RSA Identity Governance & Lifecycle menus do not display correctly in Internet Explorer (IE) 11 when using Compatibility V… 132Number of Views Error launching the Aveksa Kiosk Password-Reset-form aka Desktop Based Password Reset in RSA Identity Governance and Lifec… 57Number of Views Workflow edits and new Workflows cannot be saved when using Internet Explorer (IE) in version 7.0.0 or lower of RSA Identi… 61Number of Views After Microsoft Windows update and/or GPO changes, administrative users cannot login to RSA Authentication Manager 8.1 Sec… 466Number of Views An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x 1.23KNumber of Views
Don't see what you're looking for?