Symptom:
Client certificate authentication for SAML 1.x artifact single sign-on fails at the producer. The following error is logged in the web agent trace logs:
Setting HTTP response variable HTTP_consumer_name=from SiteMinder
For example, if the Attribute Name in the response is configured as "name" for an LDAP User Directory, the response fails.
Solution:
Verify that you create a Web Agent response under the domain FederationWebServicesDomain. The response must be as follows:
WebAgent HTTP Header variable
User Attribute
consumer_name
uid (for LDAP) or name (for ODBC)
| Copyright © 2011 CA. All rights reserved. | Email CA Technologies about this topic |