Attribute Resolver Migrating to IDP30 and generatin persistent NameId using PrincipalName

Katia katia_muser at
Mon May 11 21:07:08 EDT 2015

I've went through the post from 2 weeks ago from Sara (IdPv3 and generating
persistent NameID) and the subsequent responses and I followed the steps
detailed in the documentation to support PersistentId NameId

Content of

idp.persistentId.generator = shibboleth.ComputedPersistentIdGenerator
idp.persistentId.sourceAttribute = persistentNameIdSourceUid
idp.persistentId.salt = 2222343
idp.persistentId.algorithm = SHA
idp.nameid.saml2.legacyGenerator = shibboleth.LegacySAML2NameIDGenerator
idp.nameid.saml1.legacyGenerator =

However my attribute_resolver configuration that worked in V2 is now failing
   <resolver:AttributeDefinition id="persistentNameIdSourceUid"
nameFormat="urn:mace:shibboleth:1.0:nameIdentifier" />
          <resolver:AttributeEncoder xsi:type="enc:SAML2StringNameID"
nameFormat="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" />

In IDP30 I get this error using the same provider 

WARN [org.opensaml.saml.saml2.profile.impl.AddNameIDToSubjects:337] -
Profile Action AddNameIDToSubjects: Request specified use of an
unsupportable identifier format:

Let me know if you need more details.



View this message in context:
Sent from the Shibboleth - Users mailing list archive at

More information about the users mailing list