Juniper Secure Access as a Shib/SAML SP

Cantor, Scott cantor.2 at osu.edu
Thu Apr 18 21:25:14 EDT 2013


On 4/18/13 7:50 PM, "Patrick Le" <ple at jhmi.edu> wrote:

>I first tried to leave the field blank so that it gets the name
>identifier from the entire assertion. That allows me to login, but the
>UserID from the juniper logs is some random string of numbers which means
>nothing to us because we can¹t correlate that back to an actual user.

Well, that's your configuration, not the device. As Kevin said, chances
are you'll have the most luck using the NameID, but it's your
responsibility to configure that.

https://wiki.shibboleth.net/confluence/display/SHIB2/IdPNameIdentifier

> I tried various other methods like:
>1)     
><userAttr.urn:oid:XXX.XXX.XXXX> (where XXX is the object identifier for
>our userID attribute)

If it doesn't work, they need to document some sort of additional
requirement such as a particular attribute NameFormat, or it's possible
they don't even handle properly named attributes, and you'll have to
experiment with overriding standard names with custom ones.

-- Scott




More information about the users mailing list