-
Notifications
You must be signed in to change notification settings - Fork 24.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
NameID mapping and Single Logout #47288
Conversation
Clarify in the documentation that for SAML Single Logout to be functional, the user's principal property should be mapped from a SAML NameID and not a SAML Attribute.
Pinging @elastic/es-docs |
Pinging @elastic/es-security |
NOTE: You can select to map the SAML `NamedID` value or any other SAML attribute value to the `principal` user | ||
property. Keep in mind, however, that if a SAML attribute is mapped, the <<saml-logout, Single Logout>> functionality is | ||
not available. | ||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is this true? It shouldn't be.
We need to receive a NameID from the IdP, but I don't think we need to map it to principal
.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
You're right, I jumped the gun on this without looking at the code closely
Clarify in the documentation that for SAML Single Logout to be functional, the Identity Provider needs to release a NameID.
Clarify in the documentation that for SAML Single Logout to be functional, the Identity Provider needs to release a NameID.
Clarify in the documentation that for SAML Single Logout to be functional, the Identity Provider needs to release a NameID.
Clarify in the documentation that for SAML Single Logout to be functional, the Identity Provider needs to release a NameID.
Clarify in the documentation that for SAML Single Logout to be
functional, the Identity Provider needs to release a NameID.