NameIDFormat in SP metadata
Grady, Michael Allen
m-grady at illinois.edu
Thu Sep 20 23:11:02 EDT 2012
If I add:
<NameIDFormat>
urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
<NameIDFormat>
to an SP's metadata, what impact should that have vis-a-vis the NameIDFormat the Shib IdP would choose to send to that SP? And in what circumstances would it have that impact?
I crafted metadata for an SP that is running software that only supports SAML1.1, and furthermore expects IdP-initiated SSO (not surprising for the SAML1.1 protocol). I added the above, and made sure there was a SAML1 encoded NameID with the above format that was released to the SP. But the transient NameID was chosen instead (as the first available). So the above seemed to be ignored, and I'm wondering if that's because the SSO is IdP initiated, or because the SAML1.1 SSO endpoint is being used, or if it has no impact no matter whether there is an authn request or which protocol is used?
p.s. I did get the behavior I wanted by creating a relying party entry for the SP and only listing the above NameIDFormat for it.
--
Michael A. Grady
University of Illinois at Urbana-Champaign (retired)
217-721-3890
More information about the users
mailing list