Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[doc issue] #49

Open
nrgsap opened this issue Jan 16, 2025 · 1 comment
Open

[doc issue] #49

nrgsap opened this issue Jan 16, 2025 · 1 comment
Assignees

Comments

@nrgsap
Copy link

nrgsap commented Jan 16, 2025

Issue description

Issue

The documentation here states the Subject Name Identifier attribute in an Identity Authentication Service is sent to the application and then used by the application to identify the user.

Experiment

Based on some experiments I have done, this appears to be false in the case of Cloud ALM.

I set the SNI to Global User ID, and the self-defined attributes to be only Groups (value Identity Directory -> Groups). No email, user id, etc. are configured to be sent. I logon and am granted access to Cloud ALM successfully. Ok, maybe Cloud ALM knows my Global User ID somehow and identifies me that way.

However, when I change my Global User ID by one character in IAS, I am still able to log on as before. How is Cloud ALM able to identify me based on the wrong Global User ID?

My theories are:

  1. Cloud ALM is ignoring the SNI and using the User ID or Email typed into the logon screen.
  2. IAS automatically provisions updates to Cloud ALM.

Proposed Solution

The documentation should clarify in what sense the SNI is used to "identify" users. In the case of Cloud ALM I believe the SNI is not being used to identify users, but rather the identifier typed into the logon screen is used.

Feedback Type (Optional)

clarity

Page Title on SAP Help Portal (prefilled)

Configure the Subject Name Identifier Sent to the Application

Page URL on SAP Help Portal (prefilled)

https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/configure-subject-name-identifier-sent-to-application?version=Cloud

@ValAta ValAta self-assigned this Jan 17, 2025
@ValAta
Copy link
Contributor

ValAta commented Jan 17, 2025

Thank you for your feedback! We’ll look into it and come back to you if we have any questions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants