RSA Identity Management & Governance AuthRequest asking for a transient ID in SAML SSO integration
Originally Published: 2016-08-16
Article Number
Applies To
RSA Version/Condition: 7.0
Issue
The NameID format is as follows:
<saml2p:NameIDPolicy AllowCreate="true" Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" />
Resolution
- Log into the RSA Identity Management & Governance User Interface.
- Navigate to Admin > System and click on the Authentication tab.
- Select the SSO Authentication Source.
- Update the SAMLAuthenticatorClass value com.aveksa.server.authentication.SAMLPingAuthenticatorImpl. By default the value is set as com.aveksa.server.authentication.SAMLAuthenticatorImpl.
- Restart the application.
- After the restart, the SAMLRequest will be built on the correct profile and will create a SAMLResponse with the UnifiedUserColumn value into the NameID field.
Notes
Please make sure that the Identity Provider (IdP) set by the customer in a nameid-format. RSA Identity Management & Governance code looks at that, parses the nameid and locates it in the T_Master_Enterprise_User Table. If the user is there (and not terminated or disabled), it returns as an authentication success.
Related Articles
RSA Customer Frequently Asked Questions FAQs: Kaseya VSA Advisory 10Number of Views RSA Customer Frequently Asked Questions FAQs: FireEye Tooling Disclosure SolarWinds Advisory 9Number of Views FIM console not asking for administrative logon after applying hotfix 4Number of Views FIM standalone install asks for sql url/port with Derby 14Number of Views RSA Authentication Agent 2.0 for Microsoft AD FS Group Policy Object Template Guide 39Number of Views
Don't see what you're looking for?