9.3 Configuring the Authentication Request

Use the Authentication Request page to select the format for the name identifier that is returned in the SAML assertion. The selected attribute sets (Identity Servers > Edit > STS > Attribute Sets) determine the values that are available for the formats. If you select a format but do not specify a value, a unique value is generated.

  1. In the Administration Console, click Devices > Identity Servers > Edit > STS > Authentication Request.

  2. Select one of the following:

    None: Indicates that the SAML assertion does not contain a name identifier.

    Unspecified: Specifies that the SAML assertion contains an unspecified name identifier. For the value, select the attribute that the relying party and the identity provider have agreed to use.

    E-mail: Specifies that the SAML assertion contains the user’s e-mail address for the name identifier. For the value, select an e-mail attribute.

    X509: Specifies that the SAML assertion contains an X.509 certificate for the name identifier. For the value, select an X.509 attribute.

  3. Click OK, then update the Identity Server if you have changed the configuration.