<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Teemu, Please review CWMS in Collaboration Applications</title>
    <link>https://community.cisco.com/t5/collaboration-applications/webex-meeting-sso-existing-usernames-in-different-formats/m-p/2571733#M2909</link>
    <description>&lt;P&gt;Hi Teemu,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please review CWMS Singe Sign-On Planning Guide where all the details about CWMS SSO is documented.&amp;nbsp;&lt;A href="http://www.cisco.com/c/en/us/td/docs/collaboration/CWMS/2_5/Planning_Guide/Planning_Guide/Planning_Guide_chapter_01001.html#reference_9C2B22F088AC419490ABA90B446C1C8D"&gt;http://www.cisco.com/c/en/us/td/docs/collaboration/CWMS/2_5/Planning_Guide/Planning_Guide/Planning_Guide_chapter_01001.html#reference_9C2B22F088AC419490ABA90B446C1C8D&lt;/A&gt;&lt;/P&gt;&lt;P&gt;For NameID mapping, you will see that CWMS requires e-mail address mapping:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: 14.3999996185303px;"&gt;&lt;LI style="margin-top: 0.5em; margin-bottom: 0.5em; line-height: 1.2em;"&gt;&lt;P style="font-size: 1em; margin-top: 0.5em; margin-bottom: 0.5em; line-height: 1.2em;"&gt;It is mandatory for the SAML Assertion to carry the email address in the NameID field. Without this step, user authentication and account creation fail because Cisco WebEx Meetings Server does not permit the creation of user accounts without an associated email address.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you by any chance use something else and not e-mail address, CWMS might let you create the account, but you might most likely experience issues with Productivity Tools authentication and other issues. We've seen this happening in the field and there was&amp;nbsp;a defect submitted that was resolved in 2.5 MR1 that will prevent account creation if NameID isn't e-mail address: "&lt;STRONG&gt;CSCus04261 &lt;/STRONG&gt;SSO allows for NameID to be content besides email address"&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;-Dejan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Jan 2015 13:26:02 GMT</pubDate>
    <dc:creator>dpetrovi</dc:creator>
    <dc:date>2015-01-09T13:26:02Z</dc:date>
    <item>
      <title>Webex Meeting SSO: existing usernames in different formats</title>
      <link>https://community.cisco.com/t5/collaboration-applications/webex-meeting-sso-existing-usernames-in-different-formats/m-p/2571732#M2908</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we currently have a Webex Meeting site with local authentication (i.e. no single sign-on). On the site there are existing usernames in two different formats: "John Doe" and "jane.doe@domain.tld".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We'd now like to set&amp;nbsp;up single-sign on. I can successfully set up SSO on a test site&amp;nbsp;using MS ADFS 2.0 so that either "John Doe" or "jane.doe@domain.tld" can log in. This is done in ADFS claim rules by mapping either Display-Name or&amp;nbsp;E-Mail-Addresses to&amp;nbsp;Name ID.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any way to make this work for both formats of usernames simultaneously? I have tried creating two mappings to the claim rule (both E-Mail-Addresses and Display-Name mapped to Name ID)&amp;nbsp;and&amp;nbsp;and two different claim rules but both seem to break SSO altogether.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Teemu&lt;/P&gt;</description>
      <pubDate>Sun, 17 Mar 2019 23:47:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/webex-meeting-sso-existing-usernames-in-different-formats/m-p/2571732#M2908</guid>
      <dc:creator>Teemu Pulliainen</dc:creator>
      <dc:date>2019-03-17T23:47:34Z</dc:date>
    </item>
    <item>
      <title>Hi Teemu, Please review CWMS</title>
      <link>https://community.cisco.com/t5/collaboration-applications/webex-meeting-sso-existing-usernames-in-different-formats/m-p/2571733#M2909</link>
      <description>&lt;P&gt;Hi Teemu,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please review CWMS Singe Sign-On Planning Guide where all the details about CWMS SSO is documented.&amp;nbsp;&lt;A href="http://www.cisco.com/c/en/us/td/docs/collaboration/CWMS/2_5/Planning_Guide/Planning_Guide/Planning_Guide_chapter_01001.html#reference_9C2B22F088AC419490ABA90B446C1C8D"&gt;http://www.cisco.com/c/en/us/td/docs/collaboration/CWMS/2_5/Planning_Guide/Planning_Guide/Planning_Guide_chapter_01001.html#reference_9C2B22F088AC419490ABA90B446C1C8D&lt;/A&gt;&lt;/P&gt;&lt;P&gt;For NameID mapping, you will see that CWMS requires e-mail address mapping:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: 14.3999996185303px;"&gt;&lt;LI style="margin-top: 0.5em; margin-bottom: 0.5em; line-height: 1.2em;"&gt;&lt;P style="font-size: 1em; margin-top: 0.5em; margin-bottom: 0.5em; line-height: 1.2em;"&gt;It is mandatory for the SAML Assertion to carry the email address in the NameID field. Without this step, user authentication and account creation fail because Cisco WebEx Meetings Server does not permit the creation of user accounts without an associated email address.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you by any chance use something else and not e-mail address, CWMS might let you create the account, but you might most likely experience issues with Productivity Tools authentication and other issues. We've seen this happening in the field and there was&amp;nbsp;a defect submitted that was resolved in 2.5 MR1 that will prevent account creation if NameID isn't e-mail address: "&lt;STRONG&gt;CSCus04261 &lt;/STRONG&gt;SSO allows for NameID to be content besides email address"&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;-Dejan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jan 2015 13:26:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/webex-meeting-sso-existing-usernames-in-different-formats/m-p/2571733#M2909</guid>
      <dc:creator>dpetrovi</dc:creator>
      <dc:date>2015-01-09T13:26:02Z</dc:date>
    </item>
    <item>
      <title>&gt; It is mandatory for the</title>
      <link>https://community.cisco.com/t5/collaboration-applications/webex-meeting-sso-existing-usernames-in-different-formats/m-p/2571734#M2910</link>
      <description>&lt;P&gt;&amp;gt;&amp;nbsp;&lt;SPAN style="font-size: 14px; line-height: 17.2799987792969px; background-color: rgb(249, 249, 249);"&gt;It is mandatory for the SAML Assertion to carry the email address in the NameID field.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px; line-height: 17.2799987792969px; background-color: rgb(249, 249, 249);"&gt;So if I get this right, I don't really have any other option than changing the "John Doe" usernames&amp;nbsp;to the email format (or letting auto-account-creation create new accounts for them).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px; line-height: 17.2799987792969px; background-color: rgb(249, 249, 249);"&gt;Thank&amp;nbsp;you&amp;nbsp;for the response.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jan 2015 13:54:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/webex-meeting-sso-existing-usernames-in-different-formats/m-p/2571734#M2910</guid>
      <dc:creator>Teemu Pulliainen</dc:creator>
      <dc:date>2015-01-09T13:54:29Z</dc:date>
    </item>
  </channel>
</rss>

