IdP: Returning emailAddress as NameId in SAMLResponse Assertion

Peter Schober peter.schober at univie.ac.at
Thu Nov 21 08:52:06 EST 2013


* Kevin P. Foote <kpfoote at iup.edu> [2013-11-21 14:44]:
> On Thu, 21 Nov 2013, vyal2k wrote:
> >And the AuthnRequest contains:
> ><saml2p:NameIDPolicy Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"/>
> 
> You are probably not removing the Transient NameId from the available
> attributes at your filter.

But according to "IdP Name Identifier Selection Process"
https://wiki.shibboleth.net/confluence/display/SHIB2/IdPNameIdentifier
if the SP requests a specific format the IdP will either pick that one
or return an error to the SP.
So if everything were as the OP said, it should Just Work.
-peter


More information about the users mailing list