SAML2.0 Identity Assertion Mapping Issue
WebLogic Server Version: 12.2.1.4.0
ForgeRock IAM version 7
I've been having issue with Groups/Roles when integrating SAML2.0 with our weblogic. It seems that Groups from the saml response isn't map to WLSGroup. I know I can create a custom identity assertion mapper but just wondering if there something we could do without the custom mapper.
SAML Response
<samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" ID="s2f10db1c512cd11d7f2849d683316303215980e75" InResponseTo="_a67caa6b-3779-4335-9b78-4b8915689642" Version="2.0" IssueInstant="2021-02-04T21:55:59Z" Destination="https://mydomain/saml2/sp/acs/post">
<saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">...</saml:Issuer>