correct nameid-format
Michael Dahlberg
olgamirth at gmail.com
Thu Oct 9 11:18:02 EDT 2014
I'm trying to configure our IdP for an external SP (widencollective.com).
Authentication is successful (for the user "testuser") but immediately
after that, I get an error page from the SP that states that "the access
request was malformed". My logs show the following:
10:59:41.442 - WARN
[edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:491]
- No attribute of principal 'testuser' can be encoded in to a
NameIdentifier of required format
'urn:oasis:names:tc:SAML:2.0:nameid-format:persistent' for relying party '
https://bucknell.widencollective.com'
10:59:41.454 - INFO [Shibboleth-Audit:1028] -
20141009T145941Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|_4e53a5ba-696d-4e6e-995f-ef4bec816e1b|
https://bucknell.widencollective.com
|urn:mace:shibboleth:2.0:profiles:saml2:sso|
https://shib.bucknell.edu/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_15f35c49bb8308f399df9bf95795d0fd|testuser|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport||||
In the attribute-filter.xml file, I deny the transientID and provide the
attribute cnIdentifiedName, which is an SAML 2.0, persistent nameid
attribute:
I've done some research in the Shibboleth Wiki and I keep getting to this
page and I have no idea how this relates to my error:
https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUnsolicitedSSO
My other option is to use a transient nameid, but I've been told that is
not supported.
Any suggestions will be appreciated.
Thanks,
Mike
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141009/4f9e0636/attachment.html
More information about the users
mailing list