Juniper Secure Access as a Shib/SAML SP
Cantor, Scott
cantor.2 at osu.edu
Thu Apr 18 21:25:14 EDT 2013
On 4/18/13 7:50 PM, "Patrick Le" <ple at jhmi.edu> wrote:
>I first tried to leave the field blank so that it gets the name
>identifier from the entire assertion. That allows me to login, but the
>UserID from the juniper logs is some random string of numbers which means
>nothing to us because we can¹t correlate that back to an actual user.
Well, that's your configuration, not the device. As Kevin said, chances
are you'll have the most luck using the NameID, but it's your
responsibility to configure that.
https://wiki.shibboleth.net/confluence/display/SHIB2/IdPNameIdentifier
> I tried various other methods like:
>1)
><userAttr.urn:oid:XXX.XXX.XXXX> (where XXX is the object identifier for
>our userID attribute)
If it doesn't work, they need to document some sort of additional
requirement such as a particular attribute NameFormat, or it's possible
they don't even handle properly named attributes, and you'll have to
experiment with overriding standard names with custom ones.
-- Scott
More information about the users
mailing list