Version Affected: All
Overview
When configuring a SAML integration between SecureAuth and Tanium, authentication fails and Tanium displays the following error: Request lacks valid authentication credentials for the requested resource
Cause
Tanium's own logging does not specify what this error actually refers to, and Tanium does not publish SecureAuth-specific integration documentation. The real cause is that the email address attribute is not being sent to Tanium in the SAML assertion.
Resolution:
On the SecureAuth realm used for this integration, add a SAML Attribute under SAML Attributes / WS Federation that passes the user's email address using the following Uniform Resource Identifier (URI) as the attribute name, with the attribute's Format set to URI:
https://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
Set the attribute's Value to whichever Datastore field holds the user's email address, for example Email 1. The screenshot below shows this attribute configured with Format set to URI and Value set to Email 1.
Special Considerations
Use SP-Initiated by POST for this integration.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.