Difference between revisions of "SAML:EduPersonOrgDN"

From wikieduonline
Jump to navigation Jump to search
Line 10: Line 10:
 
     "Condition": {"StringEquals": {
 
     "Condition": {"StringEquals": {
 
       "saml:edupersonorgdn": "ExampleOrg",
 
       "saml:edupersonorgdn": "ExampleOrg",
       "saml:aud": "https://signin.aws.amazon.com/saml"
+
       "[[saml:aud]]": "https://signin.aws.amazon.com/saml"
 
     }}
 
     }}
 
   }]
 
   }]

Revision as of 14:48, 2 November 2021

https://iam.uconn.edu/supported-ldap-attributes/

https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_enable-console-saml.html

{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Principal": {"Federated": "arn:aws:iam::account-id:saml-provider/ExampleOrgSSOProvider"},
    "Action": "sts:AssumeRoleWithSAML",
    "Condition": {"StringEquals": {
      "saml:edupersonorgdn": "ExampleOrg",
      "saml:aud": "https://signin.aws.amazon.com/saml"
    }}
  }]
}

See also

Advertising: