[External] Re: NameID in SP attribute-map

Donovan, Aaron [USA] donovan_aaron at bah.com
Fri Mar 14 16:24:32 EDT 2014


Scott,

Thanks for the second set of eyes. I corrected the nameFormat in the IdP's attribute-resolver configuration to the fix the typo and the attribute is being populated as expected.

Regards,
Aaron
________________________________________
From: users-bounces at shibboleth.net [users-bounces at shibboleth.net] on behalf of Cantor, Scott [cantor.2 at osu.edu]
Sent: Friday, March 14, 2014 1:04 PM
To: Shib Users
Subject: [External]  Re: NameID in SP attribute-map

On 3/14/14, 11:24 AM, "Donovan, Aaron [USA]" <donovan_aaron at bah.com> wrote:
>
>I'm using PKI authentication on my IdP and setting the NameID with a
>format of urn:oasis:names:tc:SAML:1.1:nameid-format:X509SubjectName.

I don't have the spec handy, but assuming that's the constant value...

>It's coming through in the SAML assertion as follows.
>
><saml2:Subject><saml2:NameID
>Format="urn:oasis:names:tc:SAML:1.1:nameid-format:X509Subject"

Note that's not the same.

><Attribute id="X509SubjectName"
>  name="urn:oasis:names:tc:SAML:1.1:nameid-format:X509SubjectName">

And so that isn't going to expose anything from the assertion sample you
included.

-- Scott


--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list