SiteMinder
SiteMinder is Broadcom’s enterprise web access management & federation platform. It protects apps via agents/reverse proxies, acts as SAML 2.0 IdP/SP, and (12.8+) can operate as an OpenID Connect/OAuth 2.0 provider; legacy WS-Federation/WS-Trust are documented.
Key Capabilities
-
Standards-based federation: SAML 2.0 (IdP/SP, Web Browser SSO, SLO) with step-by-step IdP configuration and assertion delivery options.
-
OIDC/OAuth 2.0 provider: Documented instructions to configure SiteMinder as an OpenID Connect Provider, create clients, and expose authorization/token endpoints.
-
Web access management (WAM): Policy Server + Web Agents/Proxy enforce authentication, sessioning, and header/cookie injection for protected apps. (Platform docs hub.)
-
Ecosystem integration: Broadcom techdocs show integrations with Identity Manager and other Broadcom components; downloads and lifecycle info are on the support portal.
Limitations
-
Advanced OAuth profiles: Public docs focus on core OIDC/OAuth; not enough public information to confirm support for PAR, DPoP, or mTLS-bound tokens/FAPI.
-
SCIM provisioning: SiteMinder is an access/federation platform; not enough public information to confirm a general-purpose SCIM 2.0 provider/consumer in SiteMinder itself.
-
Self-hosted operations: Customers manage Policy Servers, Web Agents/Proxies, certificates, HA, and upgrades—heavier ops than SaaS IdPs.
-
Lifecycle & naming: Multiple brandings (CA SSO / CA SiteMinder / Symantec SiteMinder). Broadcom publishes EOL/EOS dates per release—validate before planning upgrades/migrations.