Identity Management (MOSC)

MOSC Banner

SAML Logout issue using transient plus email in OAM 11GR2PS3

We are integrating an an application (SP) with OAM (IdP).  The login works fine when a user authenticates we send the Subject NameID as “urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress“ with the user's email to the SP.

When the logout action is performed at the SP.  OAM gets the SAML request as “urn:oasis:names:tc:SAML:2.0:nameid-format:transient” with the same email address sent in the original assertion.   The SAML Response and the diagnostics logs state “User authenticated at IdP different from User specified in the Request message”.

I’ve tried looking through some more Oracle documents, but all leads to the same results.  OAM seems to not like the Subject as “transient” with an email.  Is there a way to setup OAM's SP configuration to use a nameid format of transient and use a profile attribute (in this case the user's email address). 

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center