ADFS 2.0 - Conditionally issuing claims
(is best place this? geneva forum has been archived.)
hi has got ideas how solve problem: access given area of relying party's application need specify area in claim.
i'm using ad group conditionally issue claim - there 2 possible claim values need issue , given user required access 1 area or other, not both. have rule checks if user part of ad group, if are, issues claim value1 otherwise issues claim value2.
we have need add third area both sets of users need access. claim needs issued dynamically. i'd able issue claim based on idp initiated login url parameter.
e.g.
access portal1 @ myrp.com:
https://federate.mydomain.com/adfs/ls/idpinitiatedsignon.aspx?logintorp=https://myrp.com&portal=portal1
access portal2 @ myrp.com:
https://federate.mydomain.com/adfs/ls/idpinitiatedsignon.aspx?logintorp=https://myrp.com&portal=portal
one option might have been have multiple relying parties configured end @ same rp have different rule sets e.g.
access portal1 @ myrp.com:
https://federate.mydomain.com/adfs/ls/idpinitiatedsignon.aspx?logintorp=https://myrp.com.portal1
access portal2 @ myrp.com:
https://federate.mydomain.com/adfs/ls/idpinitiatedsignon.aspx?logintorp=https://myrp.com.portal2
problem is, adfs won't allow multiple rps created when have same signing certificate.
i'm interested know claims in incoming set. know they're ad attributes there others e.g. "authentication time stamp" doesn't come ad must generated adfs. else in there check against. somthing referingurl - check user redirected , determine claim issue.
any ideas appreaciated.
cheers,
rhys
hi,
please try visit adapt forum better resolution.
http://social.msdn.microsoft.com/forums/en-us/geneva/threads/
thanks understanding!
best regards
elytis cheng
please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread.
Windows Server > Directory Services
Comments
Post a Comment