Juniper Secure Access as a Shib/SAML SP
Paul Riddle
paulr at umbc.edu
Fri Apr 19 15:58:35 EDT 2013
On Thu, Apr 18, 2013 at 7:50 PM, Patrick Le <ple at jhmi.edu> wrote:
> Does anyone have any experience integrating SAML 2.0 authentication
> against Juniper Secure Access with Shibboleth as the IDP?****
>
Yes, we're running a Juniper VPN and we use our Shib IdP to authenticate to
it via SAML2.
> I’m having issues getting the Juniper appliance to pick up the userID from
> the attribute assertion. On the juniper appliance under the “Auth Server”
> configuration page, there is a “User Name Template” field where you’re
> supposed to define the attribute name for the userID. Examples given by
> juniper are:****
>
> ** **
>
> Example: <assertionNameDN.uid>, uid from X509SubjectName.
> The entire assertion name identifier if not specified; Or
> <userAttr.attr>, attr from AttributeStatement attributes.****
>
> ** **
>
> ** **
>
> I first tried to leave the field blank so that it gets the name identifier
> from the entire assertion. That allows me to login, but the UserID from the
> juniper logs is some random string of numbers which means nothing to us
> because we can’t correlate that back to an actual user.
>
> Attributes won'
> Juniper support has been less than helpful, so I’m hoping I’ll get better
> luck on the shib users list. ****
>
> ** **
>
> Thanks****
>
> ** **
>
> Patrick****
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130419/a540769d/attachment.html
More information about the users
mailing list