RSA Identity Management & Governance AuthRequest asking for a transient ID in SAML SSO integration
Originally Published: 2016-08-16
Article Number
Applies To
RSA Version/Condition: 7.0
Issue
The NameID format is as follows:
<saml2p:NameIDPolicy AllowCreate="true" Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" />
Resolution
- Log into the RSA Identity Management & Governance User Interface.
- Navigate to Admin > System and click on the Authentication tab.
- Select the SSO Authentication Source.
- Update the SAMLAuthenticatorClass value com.aveksa.server.authentication.SAMLPingAuthenticatorImpl. By default the value is set as com.aveksa.server.authentication.SAMLAuthenticatorImpl.
- Restart the application.
- After the restart, the SAMLRequest will be built on the correct profile and will create a SAMLResponse with the UnifiedUserColumn value into the NameID field.
Notes
Please make sure that the Identity Provider (IdP) set by the customer in a nameid-format. RSA Identity Management & Governance code looks at that, parses the nameid and locates it in the T_Master_Enterprise_User Table. If the user is there (and not terminated or disabled), it returns as an authentication success.
Related Articles
RSA Customer Frequently Asked Questions FAQs: Kaseya VSA Advisory 10Number of Views RSA Customer Frequently Asked Questions FAQs: FireEye Tooling Disclosure SolarWinds Advisory 9Number of Views An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x 1.22KNumber of Views Authentication with SSH tools fails on Solaris asks for a password instead of passcode 38Number of Views FIM console not asking for administrative logon after applying hotfix 4Number of Views
Trending Articles
Authentication Manager Supported Hardware and Upgrade Paths RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.8 Setup and Configuration Guide Downloading RSA Authentication Manager license files or RSA Software token seed records Artifacts to gather in RSA Identity Governance & Lifecycle
Don't see what you're looking for?