Symptom
The following error occurs when authenticating to the SAP NetWeaver ABAP using SAML2.0:
SAML20 SP (client 010): Exception raised:
SAML20 SAML20 CX_SAML20_FEDERATION: Format 'transient' is not supported (or this can also be 'emailaddress' or 'unspecified' rather than 'transient') for user assignment. Long text: Format 'transient' is not supported for user assignment.
SAML20 at CL_SAML20_ENTITY->IS_NAMEID_FORMAT_SUPPORTED
The same can be checked in traces collected with Security Diagnostic tool:
or :
Format 'emailAddress' is not supported for user assignment. Details: Format 'emailAddress' is not supported for user
or
Format 'WindowsDomainQualifiedName' is not supported for user assignment.
Read more...
Environment
- SAP enhancement package 2 for SAP NetWeaver 7.0
- SAP NetWeaver 7.3
- SAP enhancement package 1 for SAP NetWeaver 7.3
- SAP NetWeaver 7.4
- SAP NetWeaver 7.5 and higher
Product
Keywords
Can't map username, username, map, login error, Identity Provider (IdP), saml2, SSO,Security Diagnostic Tool, is not supported for user assignment, emailAddress, WindowsDomainQualifiedName, Format 'unspecified' is not supported. , KBA , BC-SEC-LGN-SML , SAML 2.0 for ABAP , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.