<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 12 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";
        color:black;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
span.EmailStyle18
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body bgcolor="white" lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="color:#1F497D">Guess from what you&#8217;re saying I need to figure out how to configure OpenAM to send the user id as an attribute and ignore the NameID. Currently it&#8217;s not sending any attributes with the Assertion. Here&#8217;s the subject,
 it says the NameID is transient.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">&lt;saml:Subject&gt;<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;saml:NameID Format=&quot;urn:oasis:names:tc:SAML:2.0:nameid-format:transient&quot; NameQualifier=&quot;http://localhost:7080/openam&quot; SPNameQualifier=&quot;http://localhost:8080&quot;&gt;cGMR3nDv&#43;7sH/9P2NHP6OTVH7YJx&lt;/saml:NameID&gt;<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;saml:SubjectConfirmation Method=&quot;urn:oasis:names:tc:SAML:2.0:cm:bearer&quot;&gt;<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;saml:SubjectConfirmationData NotOnOrAfter=&quot;2012-11-14T15:43:48Z&quot; Recipient=&quot;http://localhost:8080/saml&quot;/&gt;<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;/saml:SubjectConfirmation&gt;<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">&lt;/saml:Subject&gt;<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;;color:windowtext">From:</span></b><span style="font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;;color:windowtext"> dev-bounces@shibboleth.net [mailto:dev-bounces@shibboleth.net]
<b>On Behalf Of </b>Brent Putman<br>
<b>Sent:</b> Wednesday, November 14, 2012 1:30 PM<br>
<b>To:</b> dev@shibboleth.net<br>
<b>Subject:</b> Re: Hot do I get users ID in an OpenSAML (SP) &#43; OpenAM (IdP) environment<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<p class="MsoNormal">On 11/14/12 1:34 PM, Stephen Gaines wrote:<o:p></o:p></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal">My problem is that the only type of ID I see coming from OpenAM is what appears to be an encrypted ID.
<o:p></o:p></p>
</blockquote>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;"><br>
Coming from what source in the Assertion: the NameID or an Attribute?<br>
<br>
And do you literally mean 'encrypted', which has a very specific meaning in cryptography? (as opposed to just encoded, or some sort of opaque value)&nbsp; If the SP encrypted it with a key that you hold and that you gave to them, then you decrypt it, pure and simple.&nbsp;
 OpenSAML has support for that, but you first need to verify what they are sending you.<br>
<br>
<br>
<br>
<o:p></o:p></span></p>
<p class="MsoNormal">Is there some way to have OpenSAML parse this ID?<o:p></o:p></p>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;"><br>
Well, yes, but it isn't clear what it is yet...<br>
<br>
<br>
<br>
<o:p></o:p></span></p>
<p class="MsoNormal">I need to know who is logged in and this randomly encrypted ID doesn&#8217;t provide me direct access to that information.<o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;"><br>
<br>
The phrase &quot;randomly encrypted&quot; makes me think it's perhaps not encrypted and it is merely some kind of randomly generated, opaque value.&nbsp; This is common for a NameID types like persistent and transient ID's.&nbsp; Those are typically not reversible.&nbsp; They are intended
 to be used as-is as a user identifier, and they consciously don't expose the user's identity.<br>
<br>
If they send such a NameID, it's possible that they are also sending something like a &quot;username&quot; or &quot;principal name&quot; in an Attribute value. Did you check there?<br>
<br>
It's entirely possible that the IdP isn't sending you anything like a username, esp. if you didn't configure it do to do that.&nbsp; It's certainly not a requirement or default expectation of SAML.<br>
<br>
--Brent<br>
<br>
<br>
<o:p></o:p></span></p>
</div>
</body>
</html>