Shibboleth 2.3 with SSO web client - mininum steps
lalithj
j_lalith at hotmail.com
Thu Jan 31 15:39:49 EST 2013
Thanks for the reply,
Sorry, My mistake, sn was tried only as a test run. Further reading their
docs,
What they want is either loginId or email address, which is unique. So we
will go with email address.
Looking at our logs (before the encryption) we can see the subject goes as
follows
<saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"
NameQualifier="https://ourIdp.x.com/idp/shibboleth"
SPNameQualifier="https://clientSP.com/">_99999fe8638579999999680248</saml2:NameID>
they want email address/login Id instead,
we Can't figure it looking at our attribute resolvers, from where it is
getting injected,
if am not mistaken, I can see an entry in SP Meta Data as follows,
.....
<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
........
Could it be because of that? Then to solve it can is there any way to have
email instead
Sorry if this is not the correct analysis
Thanks,
--
View this message in context: http://shibboleth.1660669.n2.nabble.com/Shibboleth-2-3-with-SSO-web-client-mininum-steps-tp7584342p7584388.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.
More information about the users
mailing list