Transient Federation within SAML 2.0

You need to make the following configuration changes for the transient federations to work from Origin Identity Provider to SP Broker to Target Service Provider.For example, if the Origin Identity Provider is on SAML 1.0 (transient), the SP Broker and the Target Service Provider also must be on transient federation.

Origin Identity Provider Configuration

  1. Go to Edit > SAML2 > Trusted Providers > (Broker IDP under the Service Providers list) > Authentication Response

  2. Enable the Transient Name ID Format and make it as Default.

Broker Identity Provider Configuration

  1. Go to Edit > SAML2 > Trusted Providers > (Origin IDP under the Identity Providers list) > Authentication Card > Authentication Request.

  2. Select the Transient Name ID Format.

  3. Go to Edit > SAML2 > Trusted Providers > (Next hop SP under the Service Providers list) > Authentication Response.

  4. Enable the Transient Name ID Format and make it as Default.

Service Provider Configuration

  1. Go to Edit> SAML2> Trusted Providers > (Broker IDP under the Identity Providers list) > Authentication Card > Authentication Request.

  2. Select the Transient Name ID Format