Skip to Content
2

Easier start by other defaults for Assertion Attributes in SAP CP Identity Authentication Service

Jul 19, 2017 at 07:20 PM

326

avatar image

Hello SAP CP Identity Authentication Service Team,

at Configure Assertion Attributes Mapping the integration with SAP Cloud Platform is described. Unfortunately the attributes are:

  • first_name
  • last_name
  • mail

This results in the following display in the SAP CP Portal Fiori Launchpad User Settings:


if the attributes would be

  • firstname
  • lastname
  • email

Then it would match the Assertion Attributes that are provided from the SAP ID Service. And it seems only when this attributes are used the Name of the user is correctly displayed when using i.e. the SAP CP Portal Fiori Launchpad User Settings:

I hope that this default setting can be changed to give customers using the SAP CP Identity Authentication Service have a easier start especially if they use it for SAP CP Applications.

Best regards
Gregor

10 |10000 characters needed characters left characters exceeded
* Please Login or Register to Answer, Follow or Comment.

2 Answers

Best Answer
Murali Shanmugham
Jul 19, 2017 at 11:48 PM
3

Hi Gregor,

I had earlier mapped the assertion attributes in SAP CP cockpit to achieve this. You have provided a good feedback to default these attributes. I will notify the relevant colleagues.

Regards,


saml.png (25.7 kB)
Show 1 Share
10 |10000 characters needed characters left characters exceeded

Hi Murali,

as the recommended setting for the mapping in the documentation is:

* to *
it would be great if the default could be changed.

Best regards
Gregor

0
Riley Rainey
Jul 20, 2017 at 01:36 PM
0

That is inconsistent, isn't it? I'm forwarding your point to the IAS PM, Gregor.

Riley

Show 6 Share
10 |10000 characters needed characters left characters exceeded

Thank you.

0

Hi Riley,

any news from the PM?

Best regards
Gregor

0

Any news from the PM Riley Rainey ?

0

Getting more detail on the Group assertions would also be helpful. Basically, the syntax to use when checking for a single AD group when the user is assigned multiple AD groups. I have had issues setting this up at every client using MS ADFS and the instructions available in the help are not complete. Would be good to have a complete and concise guide for all of the assertion configuration as the values differ depending on where authentication is going to.

0

Gregor, I'm checking now. I'll probably get a response overnight.

0
Riley Rainey

Any update?

0