SAP Knowledge Base Article - Preview

2574530 - SAML2.0: Format <format_name> is not supported for user assignment

Symptom

The following error occurs when authenticating to the SAP NetWeaver ABAP using SAML2.0:

SAML20 SP (client 010):  Exception raised:
SAML20  SAML20 CX_SAML20_FEDERATION: Format 'transient' is not supported (or this can also be 'emailaddress' or 'unspecified' rather than 'transient') for user assignment. Long text: Format 'transient' is not supported for user assignment. 
SAML20     at CL_SAML20_ENTITY->IS_NAMEID_FORMAT_SUPPORTED

The same can be checked in traces collected with Security Diagnostic tool:

SAML_transient.png

or :

Format 'emailAddress' is not supported for user assignment. Details: Format 'emailAddress' is not supported for user

or

Format 'WindowsDomainQualifiedName' is not supported for user assignment.


Read more...

Environment

  • SAP enhancement package 2 for SAP NetWeaver 7.0
  • SAP NetWeaver 7.3
  • SAP enhancement package 1 for SAP NetWeaver 7.3
  • SAP NetWeaver 7.4
  • SAP NetWeaver 7.5 and higher

Product

SAP NetWeaver 7.3 ; SAP NetWeaver 7.4 ; SAP NetWeaver 7.5 ; SAP NetWeaver Application Server for ABAP innovation package all versions ; SAP enhancement package 1 for SAP NetWeaver 7.3 ; SAP enhancement package 2 for SAP NetWeaver 7.0

Keywords

Can't map username, username, map, login error,  saml2, sso,sec_diag_tool, is not supported for user assignment, emailAddress, WindowsDomainQualifiedName, Format 'unspecified' is not supported. , KBA , BC-SEC-LGN-SML , SAML 2.0 for ABAP , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.