On Thu, Nov 24, 2022, 10:47 AM Timothy Dilbert <[email protected]> wrote:

> We're using IBM Security Verify.
>

You need to configure your IdP to send the NameID in your desired format:
https://www.ibm.com/docs/en/security-verify?topic=provider-configuring-saml-subject-mapping-attributes

If you have already done this but the IdP is still sending its own UUIDs
instead, you'll need to reach out to your IdP for assistance. There really
isn't anything on the Guacamole side to be done here.

The SAML standard dictates identity with NameIDs. Guacamole will honor
whatever value your SAML IdP says is your identity (NameID). Your IdP is
currently sending a UUID, but appears to have options to change this
behavior.

Shouldn't there be a list of attribute names in the Guacamole documentation
> that the SAML IdP should be sending over? Do you have a list of attribute
> names I should be sending?
>

No, SAML is a standard that already dictates this. Your identity is
determined by the NameID. If your identity is not coming through as
expected, you need to configure your IdP to send what you expect for the
NameID.

- Mike

Reply via email to