No NameID released

Kevin Foote kpfoote at uoregon.edu
Mon Aug 11 16:48:49 EDT 2014


On Aug 11, 2014, at 1:42 PM, David Bantz <dabantz at alaska.edu> wrote:

> 
> For OTHER relying parties /  SPs the IdP uses TransientID for the NameID, as in:
> 09:32:53.155 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:868] - Using attribute 'transientId' supporting NameID format 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient' to create the NameID for relying party 'https://secure.aleks.com/shibboleth-sp'
> 09:32:53.155 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:733] - Attempting to encrypt NameID to relying party 'https://secure.aleks.com/shibboleth-sp'
> Value = org.opensaml.saml2.core.impl.NameIDImpl at 3cb8e2d7


Is the SP requesting a specific NameID format?

Your IdP logs should show what it is choosing for the NameID or something to the effect of "no suitable attribute found for requested nameID format” 



--------
thanks
 kevin.foote



More information about the users mailing list