NameID in SP attribute-map
Cantor, Scott
cantor.2 at osu.edu
Fri Mar 14 13:04:02 EDT 2014
On 3/14/14, 11:24 AM, "Donovan, Aaron [USA]" <donovan_aaron at bah.com> wrote:
>
>I'm using PKI authentication on my IdP and setting the NameID with a
>format of urn:oasis:names:tc:SAML:1.1:nameid-format:X509SubjectName.
I don't have the spec handy, but assuming that's the constant value...
>It's coming through in the SAML assertion as follows.
>
><saml2:Subject><saml2:NameID
>Format="urn:oasis:names:tc:SAML:1.1:nameid-format:X509Subject"
Note that's not the same.
><Attribute id="X509SubjectName"
> name="urn:oasis:names:tc:SAML:1.1:nameid-format:X509SubjectName">
And so that isn't going to expose anything from the assertion sample you
included.
-- Scott
More information about the users
mailing list