Uploaded image for project: 'OpenAM'
  1. OpenAM
  2. OPENAM-8580

OpenAM should allow to use objectGUID value from AD when working with persistent NameID

    Details

    • Type: New Feature
    • Status: Resolved
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 13.0.0
    • Fix Version/s: 13.5.0
    • Component/s: SAML
    • Labels:
    • Sprint:
      AM Sustaining Sprint 20, AM Sustaining Sprint 21, AM Sustaining Sprint 23
    • Support Ticket IDs:

      Description

      Quite often AD should be handled as a read-only data store.
      There are more and more cases when regardless of this requirement, a persistent NameID-Format based SAML federation needs to work, but OpenAM currently does not have a good solution for this.

      I believe in certain cases when working with Outlook/Office365 there is actually a requirement from the SP side that the NameID value must contain an ImmutableID, which if I'm not mistaken translates to the actual objectGUID.

      Considering that objectGUID cannot be changed in AD, it would certainly fulfill the requirements around persistent NameID format, but also since the value would actually come from an existing attribute in the LDAP entry, there would be no need to store it in custom attributes either (and hence AD could remain read-only).

      Implementing this support could immensely improve our SAML interop with Microsoft products.

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                markdr Mark de Reeper
                Reporter:
                peter.major Peter Major [X] (Inactive)
              • Votes:
                0 Vote for this issue
                Watchers:
                5 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:

                  Time Tracking

                  Estimated:
                  Original Estimate - 10h
                  10h
                  Remaining:
                  Time Spent - 2h Remaining Estimate - 8h
                  8h
                  Logged:
                  Time Spent - 2h Remaining Estimate - 8h
                  2h