FIM error message:
2007-10-23 16:30:13,707, (SSOHelper.java:585), dmzuhadc011-021, , , , Unable to process the AuthnRequest message, com.rsa.fim.profile.sso.SSOProfileException: The name ID plug-in configuration for this format could not be retrievedurn:oasis:names:tc:SAML:2.0:nameid-format:persistent
As per the installation guide Step 4: Adding Service Provider Applications (for SPs only)
If you configured an SP, you can configure each target SP application to require the IdP to use a specific name identifier format and to send specific attributes about the user. This configuration is used when the SP initiates web single sign-on (SSO) and requests identity federation for a user.
Note: This step is only applicable for SPs and it is optional. If you do not specify any attributes, FIM uses the default attribute set you define for the local entity.
FIM allows you to specify what nameIDformat the SP will request from the IDP. (The text indicates that this is optional, but really the only optional part is the attribute set.) You must specify a nameIDformat for your Service Provider Application, and your SP Entity must specify a Service Provider. There is no way to configure the RSA FIM SP not to request a nameID without a format.
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x RSA Governance & Lifecycle 8.0.0 Installation Guide