Version Affected: All
Overview
When using SecureAuth's Extended SAML Attributes feature, a SAML trace may show that an attribute's name is being passed to the Service Provider (SP), but the attribute has no value.
Cause
Each Extended SAML Attribute has a Group Filter Expression field that determines which Active Directory (AD) group membership the attribute's value applies to. This field takes a regular expression, and if it is left blank, no group matches — so the SP receives the attribute's name but never receives a value for it.
Resolution
Enter a regular expression in the Group Filter Expression field that matches at least one AD group the authenticating users belong to. Entering .* matches every group and resolves the missing value in most cases; use a more specific expression if the attribute's value should only apply to particular groups.
The screenshot above shows the Group Filter Expression field set to .* on an example Extended SAML Attribute.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.