Multiple Attributes Released that can be encoded as NameID's in IdP v2.4.3

Peter Schober peter.schober at univie.ac.at
Tue Oct 27 04:08:39 EDT 2015


* Alex Olson <ako at byu.edu> [2015-10-27 02:16]:
> And both “mail” and “eduPersonPrincipalName” can be encoded as
> NameID’s, which one will end up being the NameID?

If you're saying you have encoders of both "kinds", say, enc:SAML2String and
enc:SAML2StringNameID, attached to your attribute definitions of
"mail" and "eduPersonPrincipalName" maybe it would make things more
clear if you created separate attribute definitions for the
NameID-type ones?
Either way, SAML Metadata and/or nameIDFormatPrecedence in the
appropriate relying party config are the answer for reliably
controlling the release of the right NameID.
-peter


More information about the users mailing list