Shibboleth IdP v3 beta 1 Salesforce.com Integration
Cantor, Scott
cantor.2 at osu.edu
Sat Dec 6 16:04:57 EST 2014
On 12/6/14, 1:54 PM, "Peter Schober" <peter.schober at univie.ac.at> wrote:
>
>That proably means /unencrypted/ NameID in the Subject. So it needs to
>be unencrypted wherever you put it. The IDP tries to encrypt
>assertions by default, but not the NameID in the Subject.
>That explains why it "works" in the Subject, since it will be
>unencrypted there by default.
Sadly, no, I think he's right. When I was testing, it broke until I turned
off encryption, and we were using an Attribute (unencrypted apart from the
Assertion) for the login ID. I didn't ever think to check leaving
encryption on, but switching to the NameID.
This is one of those bugs were you can't understand how you could botch
the code that badly unless you were trying.
-- Scott
More information about the users
mailing list