How can I get the Saml2SecurityToken.Assertion.Subject.NameId in the Subject form the testshib.org test server?

W O 39a0d912abc at gmail.com
Wed Oct 15 09:51:13 EDT 2014


Thank you! Your help was wonderful. I verified your input and you are
right. So I did upload a new metadata file since I uploaded my meta data a
while ago. After the upload of a the new meta data file I also receive the
NameId as expected.
Thank you for your guidance! Top!

2014-10-15 14:26 GMT+02:00 Paul Hethmon <paul.hethmon at clareitysecurity.com>:

>  The other point to understand is the format string of:
>
>  urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
>
>  Is not a format.
>
>  It is a way for an SP to convey to an IdP that they do not care what
> format they receive back. It does not have a meaning like persistent,
> transient, or email has.
>
>  Paul
>
>  On Oct 15, 2014, at 8:16 AM, Peter Schober <peter.schober at univie.ac.at>
> wrote:
>
>  <saml:Subject>
> *      <saml:NameID
>
> Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">MyId</saml:NameID>*
>
>
> Testshib only announces support for transient NameIDs, as you can see
> in the Testshib IDP's metadata.  If you're requesting something else
> in your SAML2.0 authentication request (my reading of your "I expect"
> above) that would explain the absence of the NameID in your case, but
> its presence in other cases (like in my test with the Testshib SP).
>
> So stop requesting a NameID format the IDP does not state it supports,
> I would expect that to make a difference.
>
>
> Paul Hethmon
> Chief Software Architect
> paul.hethmon at clareitysecurity.com
>
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141015/63bf1473/attachment.html 


More information about the users mailing list