IDP-initiaded SSO or IdPUnsolicitedSSO

Jehan Procaccia Jehan.Procaccia at it-sudparis.eu
Fri Oct 18 10:01:07 EDT 2013


Le 17/10/2013 23:08, Cantor, Scott a écrit :
> On 10/17/13 4:41 PM, "Jehan Procaccia" <Jehan.Procaccia at it-sudparis.eu>
> wrote:
>> oops, that was a silly cut&paste from the wiki sample/template
>> would it be more accurate to set precedence for that new custom NameID
>> based on that definition ?
> I don't understand your question, but you are misusing transient now, and
> that's also wrong.
>
> What format does the service require? That's what you have to use.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
the vendor told me that they are waiting for this kind of format 
urn:oasis:names:tc:SAML:1.1:nameid-format: Unspecified "

based on the saml reponse example message they gave me (sample message 
that they are waiting for ):

<saml:AuthenticationStatement 
AuthenticationMethod="urn:oasis:names:tc:SAML:1.0:am:password" 
AuthenticationInstant="2013-10-09T08:55:00Z">
  <saml:Subject><saml:NameIdentifier 
Format="urn:oasis:names:tc:SAML:1.1:nameid-format: Unspecified 
">*jehan.procaccia at tam-tsp.eu 
<mailto:jehan.procaccia at tem-tsp.eu>*</saml:NameIdentifier>
<saml:SubjectConfirmation><saml:ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:bearer</saml:ConfirmationMethod>
</saml:SubjectConfirmation>
</saml:Subject></saml:AuthenticationStatement>

but it is still not clear to me what is the AttributeName, I'am waiting 
for a reponse from the vendor regarding that AttributeName ...

For now with my actual configuration I am sending :

<saml1:AttributeStatement><saml1:Subject><saml1:*NameIdentifier* 
Format="urn:mace:shibboleth:1.0:nameIdentifier" 
NameQualifier="https://idp.int-evry.fr/idp/shibboleth">_11ac849b399ca1d47c52e3210dab23ee</saml1:NameIdentifier><saml1:SubjectConfirmation><saml1:ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:bearer</saml1:ConfirmationMethod>
....
<saml1:Attribute*AttributeName="urn:mace:dir:attribute-def:mail"* 
AttributeNamespace="urn:mace:shibboleth:1.0:attributeNamespace:uri">
<saml1:AttributeValue 
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
xsi:type="xs:string">*jehan.procaccia at tam-tsp.eu*</saml1:AttributeValue></saml1:Attribute></saml1:AttributeStatement></saml1:Assertion></saml1p:Response>

I still want to send my email address as the NameIdentifier for that SP, 
not the default transientId, how can I force my shibboleth IDP to do so ?
thanks .
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131018/655dfd17/attachment.html 


More information about the users mailing list