RSA Identity Management & Governance AuthRequest asking for a transient ID in SAML SSO integration
Originally Published: 2016-08-16
Article Number
Applies To
RSA Version/Condition: 7.0
Issue
The NameID format is as follows:
<saml2p:NameIDPolicy AllowCreate="true" Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" />
Resolution
- Log into the RSA Identity Management & Governance User Interface.
- Navigate to Admin > System and click on the Authentication tab.
- Select the SSO Authentication Source.
- Update the SAMLAuthenticatorClass value com.aveksa.server.authentication.SAMLPingAuthenticatorImpl. By default the value is set as com.aveksa.server.authentication.SAMLAuthenticatorImpl.
- Restart the application.
- After the restart, the SAMLRequest will be built on the correct profile and will create a SAMLResponse with the UnifiedUserColumn value into the NameID field.
Notes
Please make sure that the Identity Provider (IdP) set by the customer in a nameid-format. RSA Identity Management & Governance code looks at that, parses the nameid and locates it in the T_Master_Enterprise_User Table. If the user is there (and not terminated or disabled), it returns as an authentication success.
Related Articles
RSA Customer Frequently Asked Questions FAQs: Kaseya VSA Advisory 10Number of Views RSA Customer Frequently Asked Questions FAQs: FireEye Tooling Disclosure SolarWinds Advisory 9Number of Views Authentication with SSH tools fails on Solaris asks for a password instead of passcode 38Number of Views FIM console not asking for administrative logon after applying hotfix 4Number of Views An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x 1.23KNumber of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager Upgrade Process How to delete old or pending certificate signing requests for RSA Authentication Manager console or virtual host replaceme…
Don't see what you're looking for?