Shibboleth IdP v3 beta 1 Salesforce.com Integration

Cantor, Scott cantor.2 at osu.edu
Sat Dec 6 16:04:57 EST 2014


On 12/6/14, 1:54 PM, "Peter Schober" <peter.schober at univie.ac.at> wrote:
>
>That proably means /unencrypted/ NameID in the Subject. So it needs to
>be unencrypted wherever you put it. The IDP tries to encrypt
>assertions by default, but not the NameID in the Subject.
>That explains why it "works" in the Subject, since it will be
>unencrypted there by default.

Sadly, no, I think he's right. When I was testing, it broke until I turned 
off encryption, and we were using an Attribute (unencrypted apart from the 
Assertion) for the login ID. I didn't ever think to check leaving 
encryption on, but switching to the NameID.

This is one of those bugs were you can't understand how you could botch 
the code that badly unless you were trying.

-- Scott



More information about the users mailing list