Difference between revisions of "SAML:EduPersonOrgDN"

From wikieduonline
Jump to navigation Jump to search
m (Welcome moved page EduPersonOrgDN to SAML:EduPersonOrgDN)
 
(10 intermediate revisions by the same user not shown)
Line 1: Line 1:
 
https://iam.uconn.edu/supported-ldap-attributes/
 
https://iam.uconn.edu/supported-ldap-attributes/
  
* {{LDAP}}
+
Enabling SAML 2.0 federated users to access the AWS Management Console: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_enable-console-saml.html
 +
{
 +
  "Version": "2012-10-17",
 +
  "Statement": [{
 +
    "Effect": "Allow",
 +
    "Principal": {"Federated": "arn:aws:iam::account-id:saml-provider/ExampleOrgSSOProvider"},
 +
    "Action": "[[sts:AssumeRoleWithSAML]]",
 +
    "Condition": {"StringEquals": {
 +
      "saml:edupersonorgdn": "ExampleOrg",
 +
      "[[saml:aud]]": "https://signin.aws.amazon.com/saml"
 +
    }}
 +
  }]
 +
}
 +
 
 +
== Related ==
 +
* <code>[[AssumeRolePolicyDocument]]</code>
 +
* http://doc.isilon.com/ECS/3.5/DataAccessGuide/GUID-BA49B495-6E0A-445B-A93E-EDF3DECB4B40.html
 +
 
 +
[[SAML:aud]] https://[[signin.aws.amazon.com]]/saml
 +
[[SAML:iss]]
 +
[[SAML:sub]]
 +
[[SAML:sub_type]]
 +
 
 +
== See also ==
 +
* {{AWS SAML}}
 +
* {{SAML}}
 +
 
 +
[[Category:AWS]]
 +
[[Category:SAML]]

Latest revision as of 18:47, 4 November 2021

Advertising: