NameID in SP attribute-map

Cantor, Scott cantor.2 at osu.edu
Fri Mar 14 13:04:02 EDT 2014


On 3/14/14, 11:24 AM, "Donovan, Aaron [USA]" <donovan_aaron at bah.com> wrote:
>
>I'm using PKI authentication on my IdP and setting the NameID with a
>format of urn:oasis:names:tc:SAML:1.1:nameid-format:X509SubjectName.

I don't have the spec handy, but assuming that's the constant value...

>It's coming through in the SAML assertion as follows.
>
><saml2:Subject><saml2:NameID
>Format="urn:oasis:names:tc:SAML:1.1:nameid-format:X509Subject"

Note that's not the same.

><Attribute id="X509SubjectName"
>  name="urn:oasis:names:tc:SAML:1.1:nameid-format:X509SubjectName">

And so that isn't going to expose anything from the assertion sample you
included.

-- Scott




More information about the users mailing list