Previous Topic: Mapping Assertion Attributes to Application Attributes (SAML Only)Next Topic: Construct Attribute Mapping Rules Using the Proper Syntax


Using the Application Attributes Definitions Table

You define attribute mapping rules in the Application Attributes Definitions table of the Application Integration dialog.

The Application Attribute and Assertion Attribute columns are populated based on the assertion attributes that are specified for the remote Producer or IdP entity. You configure these attributes at this local relying party. The assertion attribute name is entered for the Application Attribute column. The equivalent Unified Expression Language (UEL) string is entered in the Assertion Attribute(s) column.

Administrators or application integrators at the relying party must know the following information to configure attribute mapping:

Gather the names of the application and assertion attributes from the necessary parties before setting up attribute mapping.

The application attributes must reflect the attributes that are used by the target application so you must modify the default values to suit the application. You obtain the application attributes from an out-of-band communication with the application administrator.

Use the Expression Builder to Build Mapping Rules

The UI provides an expression builder to aid in the construction of mapping rules. Access the expression builder by selecting the slider button (<<) to the right of the Assertion Attribute(s) field. The slider button reveals a blank field and pull-down arrow. Select the arrow to see a list of assertion attributes and special characters that you can use to compose a mapping. Click the slider button (>>) to hide the expression builder.

The Assertion Attributes list from the expression builder is pre-populated based on the assertion attributes that are specified for the remote Producer or IdP entity, which you configure at this local relying party. You can specify entries manually as long as you know the attribute is in the assertion. You do not have to use only the options from the expression builder menu.

The Special Characters list contains characters, such as commas and percent signs that you can use to build a mapping rule. You can select a character from the list or can enter the character manually.

Important! When you enter assertion attributes in this table, they are case-sensitive relative to how the assertion attribute is specified at the remote asserting party. The cases must match. If CA SiteMinder® Federation Standalone is at both sides of the partnership, the attributes are specified in the NameID and Attributes step of the remote IdP Partnership wizard. Obtain the assertion attributes in an out-of-band communication with the partner or by importing metadata.

After the mapping rules are defined, CA SiteMinder® Federation Standalone places the data in a legacy cookie, an open format cookie, or an HTTP header and sends the data to the application. You specify the delivery method in the Target Application section of the Application Integration dialog.

Modify and Delete Mappings

You can change or remove attribute mappings in the Application Attributes Definitions table at any time.

To modify a mapping

  1. Place your cursor in any of the fields in the row you want to modify and enter the new text. You can also use the expression builder to append additional values to the end of the current expression.
  2. Save the change by clicking Next to advance to the end of the wizard.

To delete a mapping

  1. Click the trash barrel in the Delete column for the entry you want to remove.
  2. Save the change by clicking Next to advance to the end of the wizard.