Shibboleth 2.3 with SSO web client - mininum steps

lalithj j_lalith at hotmail.com
Thu Jan 31 15:39:49 EST 2013


Thanks for the reply,

Sorry, My mistake, sn was tried only as a test run. Further reading their
docs,

What they want is either loginId or email address, which is unique. So we
will go with email address.

Looking at our logs (before the encryption) we can see the subject goes as
follows

<saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"
NameQualifier="https://ourIdp.x.com/idp/shibboleth"
SPNameQualifier="https://clientSP.com/">_99999fe8638579999999680248</saml2:NameID>

they want email address/login Id instead,

we Can't figure it looking at our attribute resolvers, from where it is
getting injected,

if am not mistaken, I can see an entry in SP Meta Data as follows,
.....

<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
........

Could it be because of that?  Then to solve it can is there any way to have
email instead

Sorry if this is not the correct analysis

Thanks,



--
View this message in context: http://shibboleth.1660669.n2.nabble.com/Shibboleth-2-3-with-SSO-web-client-mininum-steps-tp7584342p7584388.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.


More information about the users mailing list