Forum Discussion

AP_129594's avatar
AP_129594
Icon for Nimbostratus rankNimbostratus
Aug 19, 2015

SAML SP required a value for NameID Format

We are on ver 11.5.3 and have an IdP instance binding to Concur SP. The SP required the value name of the emailAddress spell out inside NameID Format, i.e. testemail@domain.com I believe this is a SAML artifact binding which will be available on version 11.6? Our device is max out to upgrade, is there a way that we can use an iRule to resolve this?

 

4 Replies

  • No, Concur does not need/use SAML Artifact- they use simple HTTP POST binding. APM most certainly works with Concur for federation needs, all you need to do is specify email address as the format of the Subject in the IDP definition.

     

    Please post back if you have not been able to get it resolved.

     

    • 0_171810's avatar
      0_171810
      Icon for Nimbostratus rankNimbostratus
      Michael, I finally get it to work by enable Split domain from full username. Users will have to login with email address instead of UID. Appreciate your advice.
  • No, Concur does not need/use SAML Artifact- they use simple HTTP POST binding. APM most certainly works with Concur for federation needs, all you need to do is specify email address as the format of the Subject in the IDP definition.

     

    Please post back if you have not been able to get it resolved.

     

    • 0_171810's avatar
      0_171810
      Icon for Nimbostratus rankNimbostratus
      Michael, I finally get it to work by enable Split domain from full username. Users will have to login with email address instead of UID. Appreciate your advice.