Shibboleth 2.3 with SSO web client - mininum steps
Cantor, Scott
cantor.2 at osu.edu
Thu Jan 31 15:58:30 EST 2013
On 1/31/13 3:39 PM, "lalithj" <j_lalith at hotmail.com> wrote:
>
>we Can't figure it looking at our attribute resolvers, from where it is
>getting injected,
Peter provided the links you need to read.
>if am not mistaken, I can see an entry in SP Meta Data as follows,
>.....
>
><NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDF
>ormat>
>........
>
>Could it be because of that? Then to solve it can is there any way to
>have
>email instead
If the SP wants a different form, then it should say so in its metadata,
but that is rarely involved in the process and certainly has nothing to do
with why the IdP is doing what it's doing. If you want to change things,
you need to determine a NameID Format to use, apply the right kind of
AttributeEncoder in the attribute definition, and release the underlying
attribute in your filter policy.
-- Scott
More information about the users
mailing list