IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  SAML Authentication configuration

    Posted Tue June 27, 2023 01:59 AM
    Hi,
     
    I have Guardium 11.5 and I tried to implement SAML authentication with LDAP users. 
    After I applied the setting I get Guardium Gui but with the error - "SAML assertion does not contain role attribute".
    Is anyone done this and knows how to config the role attribute with LDAP users? 
     
     
     
    Thanks,
    Eden.


    ------------------------------
    Eden Amsalem
    ------------------------------


  • 2.  RE: SAML Authentication configuration

    Posted Tue June 27, 2023 02:09 PM

    Hi Eden, IMO, Guardium is expecting a SAML assertion from Identity Provider(IDP) with user attributes that would match the guardium policy. Please check the assertion from IDP is valid by running a SAML tracer plugin in browser.

    Below is a link to IBM docs

    Configuring authentication - IBM Documentation

    Regards,

    Rama



    ------------------------------
    Rama Yenumula
    ------------------------------



  • 3.  RE: SAML Authentication configuration

    Posted Thu June 29, 2023 07:08 AM

    Hi Rama,

    I'm working with this link. 

    The part of "How to authorize" with LDAP User is what I'm trying to understand because the "Role Attribute" is a required field and I'm not sure how to config it. 

    Do I have to config this attribute on the IDP side as "Custom Attribute Mapping" with all the Guardium Roles that we use for LDAP User login to the GUI? 

    Thanks,

    Eden.



    ------------------------------
    Eden Amsalem
    ------------------------------



  • 4.  RE: SAML Authentication configuration

    Posted Thu July 06, 2023 07:03 AM

    Hi,

    Just updating that I had a case on this topic and the support wrote that a fix should be released at the end of the month.

    Best regards,

    Eden.



    ------------------------------
    Eden Amsalem
    ------------------------------



  • 5.  RE: SAML Authentication configuration

    Posted Fri September 01, 2023 01:57 AM

    Hi Eden,

    Was the fix delivered for this? If yes, could you please share the details?

    Regards,

    Sanket



    ------------------------------
    Sanket Garode
    ------------------------------