Remote Attribute: Specify the name of the attribute defined at the external provider. The text
for this field is case sensitive.
A value is optional if you are mapping a local attribute. If you leave this field blank, the
system sends an internal value that is recognized between Identity Servers.
For a SAML 1.1 identity consumer (service provider), a name identifier received in an
assertion is automatically given a remote attribute name of saml:NameIdentifier. This
allows the name identifier to be mapped to a profile attribute that can then be used in
policy definitions.
A value is required if you are mapping a constant.
An attribute set with a constant is usually set up when the Identity Server is acting as an
identity provider for a SAML or Liberty service provider. The name must match the
attribute name that the service provider is using.
Remote namespace: Specify the namespace defined for the attribute by the remote system:
If you are defining an attribute set for LDAP, select none. If you want a service provider to
accept any namespace specified by an identity provider, select none. If you want an
identity provider to use a default namespace, select none. The
urn:oasis:names:tc:SAML:1.0:assertion
If you are defining an attribute set for CardSpace, select the following:
http://schema.xml/soap.org/ws/2005/05/identity/claims
If you are defining an attribute set for WS Federation, select the radio button next to the
text box, then specify the following name in the text box.
http://schemas.xmlsoap.org/claims
If you want to specify a new namespace, select the radial button by the text box, then
specify the name in the text box.
Remote format: Select one of the following formats:
unspecified: Indicates that the interpretation of the content is implementation-specific.
uri: Indicates that the interpretation of the content is application-specific.
basic: Indicates that the content conforms to the xs:Name format as defined for attribute
profiles.
6 Click OK.
The system displays the map settings on the Define Attributes page, as shown below:
You can continue adding as many attributes as you need.
7 Click Finish after you created the map.
The system displays the map on the Attribute Sets page, as well as indicating whether it is in
use by a provider.
8 (Conditional) To configure a provider to use the attribute set, see
Attributes for a Trusted Provider," on page
value is sent as the default.
Section 7.6, "Selecting
199.
Defining Shared Settings 175
Need help?
Do you have a question about the ACCESS MANAGER 3.1 SP2 - IDENTITY SERVER GUIDE 2010 and is the answer not in the manual?
Questions and answers