Review of the Authorization extension shows that the extension reads in this configuration element and then makes decisions based on the value.This provides a means for someone to enter other users that could be considered System Users or System Administrators.To grant full trust to your assembly open the rssrvpolicy.config file. Best practice would dictate using a strong name membership condition by using a public key blob.

Authentication failed error validating saml message

The first post in this series focused on creating some core validation logic to validate a user request.

With the core validation completed the next step is to wire up all the pieces required by SQL Reporting Services.

Leveraging the Validation Manager logic from the previous post the logic for these methods becomes simple.

A lot of the logic below is from the Forms Authentication sample.

Is Valid Principal Name and Logon User use the Validation Manager.

The other extension is the IAuthorization Extension.

Similar changes are made to the Report Server web.config file.

By default this is located in the C:\Program Files\Microsoft SQL Server\MSRS10_50. Configuration changes also need to be made to the rsreportserver.config file.

The last piece is configuration and changing the various configuration files in SSRS so that the custom security extension works.

