Skip to main content

Известные ограничения

Если у пользователя нет полей из Mapping переменных (например, почты) необходимо выполнить следующие действия:

  • создать правила для Relying Party Trust для ранее созданного стенда;
  • правой кнопкой мыши нажать на созданный ранее стенд Edit Claim Issuance Policy (рис.):

Правило 1:

c:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname", Issuer == "AD AUTHORITY"]
=> issue(store = "Active Directory", types = ("http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname"), query = ";objectSID,mail,givenName,sn;{0}", param = c.Value);

Правило 2:

c:[Type == "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"]
=> issue(Type = "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier", Issuer = c.Issuer, OriginalIssuer = c.OriginalIssuer, Value = c.Value, ValueType = c.ValueType, Properties["http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/format"] = "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress");

Если добавить Relying Party Trust не получается из-за отсутствия поддержки TLS выше версии 1.0 на стороне ADFS, то следует рассмотреть рекомендации по внесению изменений от Microsoft, приведенные в соответствующих статьях.

Чтобы добавить фото пользователя из Active Directory, необходимо выполнить команду:

c:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname", Issuer == "AD AUTHORITY"]
=> issue(store = "Active Directory", types = ("thumbnailPhoto"), query = ";thumbnailPhoto;{0}", param = c.Value);