Shibboleth IdP v3 beta 1 Salesforce.com Integration
Peter Schober
peter.schober at univie.ac.at
Sat Dec 6 08:54:13 EST 2014
* Mark Boyce <Mark.Boyce at ucop.edu> [2014-12-06 01:13]:
> We were successful using an attribute, but only without encryption.
> Adding encryption forced us to revert to using a nameID / Subject
> rather than attribute. Salesforce supposedly supports both. Seems
> the choice is attribute without encryption or encryption and send
> nameID/Subject.
That proably means /unencrypted/ NameID in the Subject. So it needs to
be unencrypted wherever you put it. The IDP tries to encrypt
assertions by default, but not the NameID in the Subject.
That explains why it "works" in the Subject, since it will be
unencrypted there by default.
-peter
More information about the users
mailing list