locked
Not getting NameID-EmailAddress in the generated AD FS 2 SAML assertion RRS feed

  • Question

  • Hi,

    We are establishing federation using ADFS 2.0(IdP) and SiteMinder(SP), after authentication on ADFS(IdP) in SiteMinder we are not getting NameId-emailAddress in the generated assertion in SiteMinder and seems to be because of that only we are getting below error in SiteMinder:

    java.lang.LinkageError: loader constraints violated when linking org/xml/sax/ErrorHandler class

    However we've already created different Claim Rules for NameId-EmailAddress on the Relying Party Trust but in the generated assertion we are not getting NameId-EmailAddress of the currently login user.

    Please assist in resolving this error.

    Thanks

    Vaibhav
    Monday, December 28, 2009 1:51 PM

Answers

  • I followed up via e-mail with Vaibhav.  For other customers who hit this problem, the root cause was that the authenticating user did not have an e-mail address configured in AD.

    Thus, when they authenticated, no e-mail address claim could be retrieved from AD, and no NameID could be generated based off of their e-mail address.
    Monday, January 4, 2010 7:17 PM

All replies

  • I followed up via e-mail with Vaibhav.  For other customers who hit this problem, the root cause was that the authenticating user did not have an e-mail address configured in AD.

    Thus, when they authenticated, no e-mail address claim could be retrieved from AD, and no NameID could be generated based off of their e-mail address.
    Monday, January 4, 2010 7:17 PM
  • Please direct any further questions about pre-release versions of AD FS to the forum at http://social.msdn.microsoft.com/Forums/en-US/Geneva/threads

    Thanks!
    Colin

    Monday, January 4, 2010 7:32 PM