I have been tasked with setting up SSO with our Jira (on-premise) v8.5.6 environment. I am unsure what claims rule to use with the built-in SSO option. The instructions state this:
- Make sure that AD FS > Trust Relationships > Relying Party Trusts > (your application) > Edit Claim Rules.. > Issuance Transform Rules use the same LDAP attribute for outgoing Name ID claim as Directory > Configuration > User name attribute in your Atlassian application. You'll need to create this rule if it doesn't exist.
I had our Jira administrator check the "User name" attribute in Jira and it says "User Name Attribute: sAMAccountName". So I setup a claims rule to map "sAMAccountName" to "Name ID". But this does not work - it tells me:
We can't log you in right now
This may be for a variety of reasons, we suggest trying again.
If that doesn't work, contact your JIRA administrator for help.
So either I have the wrong claims rule setup or something else is not working. If someone could confirm for me I am using the correct claims rule, then I can at least start looking somewhere else for the problem. If this is wrong rule, could someone let me know what I should be using instead?
Thanks
NK