RSA Identity Management & Governance AuthRequest asking for a transient ID in SAML SSO integration
Originally Published: 2016-08-16
Last Modified: 2023-10-06
Article Number
Applies To
RSA Version/Condition: 7.0
Issue
The NameID format is as follows:
<saml2p:NameIDPolicy AllowCreate="true" Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" />
Resolution
- Log into the RSA Identity Management & Governance User Interface.
- Navigate to Admin > System and click on the Authentication tab.
- Select the SSO Authentication Source.
- Update the SAMLAuthenticatorClass value com.aveksa.server.authentication.SAMLPingAuthenticatorImpl. By default the value is set as com.aveksa.server.authentication.SAMLAuthenticatorImpl.
- Restart the application.
- After the restart, the SAMLRequest will be built on the correct profile and will create a SAMLResponse with the UnifiedUserColumn value into the NameID field.
Notes
Please make sure that the Identity Provider (IdP) set by the customer in a nameid-format. RSA Identity Management & Governance code looks at that, parses the nameid and locates it in the T_Master_Enterprise_User Table. If the user is there (and not terminated or disabled), it returns as an authentication success.
Related Articles
RSA Authentication Agent 2.0 for Microsoft AD FS Group Policy Object Template Guide 39Number of Views RSA Authentication Agent 2.0.2 for Microsoft AD FS Administrator's Guide 24Number of Views An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x 1.24KNumber of Views RSA Authentication Agent 2.0 for Microsoft AD FS Release Notes 10Number of Views Microsoft Active Directory Federation Services - Relying Party Configuration - RSA Ready Implementation Guide 26Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Unable to login to RSA Authentication Manager Security Console as super admin Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x
Don't see what you're looking for?