Juniper Secure Access as a Shib/SAML SP

Kevin P. Foote kpfoote at iup.edu
Thu Apr 18 21:20:56 EDT 2013


On Thu, 18 Apr 2013, Patrick Le wrote:

> Does anyone have any experience integrating SAML 2.0 authentication against Juniper Secure Access with Shibboleth as the IDP?

No. Just guesses as with most vendor packages.

> I'm having issues getting the Juniper appliance to pick up the userID from the attribute assertion. On the juniper appliance under the "Auth Server" configuration page, there is a "User Name Template" field where you're supposed to define the attribute name for the userID. Examples given by juniper are:
>
> Example: <assertionNameDN.uid>, uid from X509SubjectName.
> The entire assertion name identifier if not specified; Or
> <userAttr.attr>, attr from AttributeStatement attributes.
>
>
> I first tried to leave the field blank so that it gets the name identifier from the entire assertion. That allows me to login, but the UserID from the juniper logs is some random string of numbers which means nothing to us because we can't correlate that back to an actual user. I tried various other methods like:

What are you setting the NameID to for this RP (SP). Guessing that what you package up here for you assertions nameId 
wise will end up as the UserID at your device.


------
thanks
  kevin.foote


More information about the users mailing list