Google Apps + v3 Idp (again)
Dave Perry
Dave.Perry at hull-college.ac.uk
Thu Apr 14 10:30:04 EDT 2016
I need to enter my full work email address into google's login form, for it to trigger the shibboleth login.
Our login names (staff or student ID) are completely different, and we don't store them on google at all when provisioning accounts via GADS.
I tried creating a username of mystaffID at hull-college.ac.uk on google as an experiment, then changed the attribute resolver google-principal to use sAMAccountName (so the NameID bean definition would use it to). And the metadata to ask for a nameid-format:unspecified). But it just changed it to be a transient ID and set something google would be even more clueless about.
Dave
_________________________________________________
Dave Perry
eLearning Technologist, Hull College Group
Room L34 - Queens Gardens Library
Wilberforce Drive, Queen's Gardens, Hull, HU1 3DG
Extension 2230 / Direct Dial 01482 381930
* Need a fast reply? Try elearning at hull-college.ac.uk *
-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: 14 April 2016 15:10
To: Shib Users
Subject: RE: Google Apps + v3 Idp (again)
> That (with the odd change) has got me to the same point I reached
> yesterday
> - I have a SAML response which has my email address in the NameID, in
> the right format according to DEBUG. But google is still rejecting it.
> No attribute beyond the nameID being released.
And you're 100% sure that the user accounts in Google are identified with the full address? What happens if you pass only the username?
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
**********************************************************************
This message is sent in confidence for the addressee
only. It may contain confidential or sensitive
information. The contents are not to be disclosed
to anyone other than the addressee. Unauthorised
recipients are requested to preserve this
confidentiality and to advise us of any errors in
transmission. Any views expressed in this message
are solely the views of the individual and do not
represent the views of the College. Nothing in this
message should be construed as creating a contract.
Hull College Group owns the email infrastructure, including the contents.
Hull College Group is committed to sustainability, please reflect before printing this email.
**********************************************************************
TEXT
More information about the users
mailing list