no NameID in an unsolicited SAML2 Response

Tom Scavo trscavo at gmail.com
Tue Sep 3 10:32:17 EDT 2013


On Thu, Aug 15, 2013 at 4:19 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>
> Omitting a NameID, though unrelated, is basically an attribute release
> matter but NameID selection is very complicated and can involve metadata
> and request settings from the SP.

In my case, I'm doing unsolicited SSO and there are no
<md:NameIDFormat> elements in metadata so the IdP is choosing to not
send a NameID. That's okay, I control the IdP, but an IdP that
supports SLO should send a NameID, right? I mean, I suppose it could
choose not to send a NameID in that case but that seems to contradict
its claim that it supports SLO.

What does the Shib IdP do in this case? Does the SAML spec have
anything to say about this?

Thanks,

Tom


More information about the users mailing list