Previous Topic: Resource Partner Properties Dialog--Users Tab

Next Topic: Resource Partner Properties Dialog--General Tab

Resource Partner Properties Dialog--Name IDs Tab

The Name IDs tab is where you configure the Name Identifier, which names a user in a unique way in the SAML assertion. The format of the Name Identifier establishes the type of content used for the ID. For example, the format might be the User DN, in which case the content might be a uid.

Name ID Format

Specifies the format for the Name ID. Pick one of the following options:

For a description of each format, see Assertions and Protocols for the OASIS Security Assertion Markup Language (SAML) V2.0 specification (sstc-saml-core-2.0-cd-04.pdf).

Name ID Type Group Box

The Name ID group box contains radio buttons that specify the Name Identifier type. The selections are:

Static

Indicates that the Name Identifier is the value in the Static Value field. Activates the Static Value field; disables other controls.

User Attribute

Indicates the Name Identifier is specified in the Attribute Name field. Activates the Attribute Name field; disables other controls.

DN Attribute

Indicates the Name Identifier is specified by an attribute associated with a DN. Activates the User Attribute field, the DN Spec field, and the Allow Nested Groups check box; disables the Static Value field.

Allow Nested Groups

Indicates that nested groups are allowed when selecting the DN. Enabled if the DN Attribute Radio Button is selected.

Name ID Fields Group Box

Contains fields that specify information about the selected Name Identifier. The fields in this group box are context-sensitive, being determined according to the Name ID Type selection.

Static Value

Specifies the static text value that will be used for all name identifiers for this Service Provider.

User Attribute

Specifies the name of the user attribute which contains the name identifier, or the attribute associated with a group or organizational unit DN.

DN Spec

Specifies the group or organizational unit DN to be used for obtaining the associated attribute to be used as the name identifier.

Lookup button

Opens the SiteMinder User Lookup dialog to locate the user group and select a DN to populate the DN Spec field.

More Information:

Specify Name IDs for WS-Federation Assertions