NameID Format

Michael Dahlberg olgamirth at gmail.com
Thu Oct 1 13:06:09 EDT 2015


On Thu, Oct 1, 2015 at 12:35 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> On 10/1/15, 12:07 PM, "users on behalf of Michael Dahlberg" <
> users-bounces at shibboleth.net on behalf of olgamirth at gmail.com> wrote:
>
> >    <resolver:AttributeDefinition id="userEmail"
> xsi:type="ad:PrincipalName" sourceAttributeID="mail" >
>
> I'm pretty sure you can't use sourceAttributeID with that plugin, it's
> whole purpose is to source from the principal name. I thnk you want
> ad:Simple if you want a separate attribute definition sourced from mail.
>

You're absolutely correct ... and that fixed the problem.  I guess I should
know why I'm "copying-and-pasting" something first.

However, I thought PrincipalName was an attribute definition not a plugin.
Am I incorrect?

Also, I found this page which talks about MetadatProviders and their
xsi:types but doesn't describe Simple or PrincipalName.

https://wiki.shibboleth.net/confluence/display/SHIB2/IdPMetadataProvider

Do you know any other parts that describe the "xsi:type" definition


>
> >And I am releasing the attribute in the attribute-filter file:
> >
> >
> >    <afp:AttributeFilterPolicy>
> >        <afp:PolicyRequirementRule
> xsi:type="basic:AttributeRequesterString" value="benefitfocus.com:sp" />
>
> Looks fine, assuming that invalid entityID is what they're using. It will
> work, but isn't legal though.


It looked strange to me as well, but I thought that was because of my lack
of experience.  That entityID does work though.

Thanks again for your help.  I appreciate it.

Mike
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20151001/0f7a030d/attachment.html>


More information about the users mailing list