organizationalUnit attribute resolver breaks Google NameID
Cantor, Scott
cantor.2 at osu.edu
Tue Oct 16 19:35:38 EDT 2012
On 10/16/12 7:16 PM, "Don Faulkner" <donf at uark.edu> wrote:
>What was "donf" in the first log line is
>"_e1efc96c3a39693be819220f16e117d7" in the second. I think this is the
>problem. What I don't understand is what's causing it.
It isn't the problem, not based on anything you posted anyway. But your
policy doesn't specifically prevent the transientID option from being used
as a NameID, and the IdP doesn't guarantee anything when you don't give it
any guidance on what NameID format to use.
>Also, a possibly-related question. Is there a "better" way to handle
>Google Apps instead of using a specific RelyingParty?
That depends what you're using the RelyingParty for.
Anyway, your main issue is with NameID format selection (see wiki for
details on how that works).
-- Scott
More information about the users
mailing list