Google Apps - Invalid Email

Greg Haverkamp gahaverkamp at lbl.gov
Thu Oct 29 02:16:09 EDT 2015


On Wed, Oct 28, 2015 at 10:42 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> > and there are no errors in the logs.  It also tests successfully with
> TestShib.  This is the applicable attribute resolver and filter
> configurations.
>
> You can't make this work without forcing the NameID format selection
> process to choose the "unspecified" format, and the only way to do that is
> via a relying party override and the nameIDFormatPrecedence property.
>

While finishing my initial configuration of v3 last night, I decided to
take a whirl with the recommendation in the documentation to try other than
"unspecified" for Google (and Service-Now and Taleo).  Google doesn't seem
to care which Format is sent, and I was able to successfully able to login
with arbitrary Formats, as configured in my metadata for those providers.
 (I thought I was going to have a fourth, but I just talked a vendor down
from requiring "unspecified" or "persistent" - even though "persistent"
clearly wasn't what they wanted.)

Greg
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20151028/45b15578/attachment.html>


More information about the users mailing list