Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

ECS 3.6.2 Data Access Guide

PDF

Attributes in SAML assertion

The following attributes are required in SAML assertion.

  • https://aws.amazon.com/SAML/Attributes/RoleSessionName
  • https://aws.amazon.com/SAML/Attributes/Role
NOTE:
  • The Role attribute must be of the format SAML Provider URN, Role URN to be used from ECS for an AD Group.
  • If you must use saml:edupersonorgdn, then oid attribute must also be present in the SAML assertion as urn:oid:1.3.6.1.4.1.5923.1.1.1.3. However, it is optional to use this attribute.

For example:

<AttributeStatement>
         <Attribute Name="https://aws.amazon.com/SAML/Attributes/RoleSessionName">
            <AttributeValue>Bob@emc.com</AttributeValue>
         </Attribute>
         <Attribute Name="https://aws.amazon.com/SAML/Attributes/Role">
            <AttributeValue>urn:ecs:iam::s3:saml-provider/provider1,urn:ecs:iam::s3:role/<Idp>-Dev</AttributeValue>
            <AttributeValue>urn:ecs:iam::s3:saml-provider/provider1,urn:ecs:iam::s3:role/<Idp>-Production</AttributeValue>
         </Attribute>
         <Attribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.3">
            <AttributeValue>ECS</AttributeValue>
         </Attribute>
      </AttributeStatement>

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\