IdP Initiated SSO

Michael Dahlberg olgamirth at gmail.com
Wed Aug 31 13:27:30 EDT 2016


>
> On Wed, Aug 31, 2016 at 1:18 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>
>> On 8/31/16, 1:08 PM, "users on behalf of Michael Dahlberg" <
>> users-bounces at shibboleth.net on behalf of olgamirth at gmail.com> wrote:
>>
>> >    On a related note, is the option to encrypt/not encrypt the nameID
>> different when using
>> > Unsolicited SSO?
>>
>> Nope.
>>
>> >  The reason I ask is because in the bean for this entityId in the
>> relying-party file, I
>> > have the following line:
>>
>> That's the default, so there's no reason to do that.
>>
>> >    Unfortunately, the nameId looks like its still being encrypted
>>
>> I can guarantee you it's not. Transient IDs are not encrypted, they're
>> simply not readable.
>>
>>
>>
> My apologies; its actually a persistent ID.  Does that make a difference?
>

Also, its a computed ID  and the source attribute is returned correctly via
LDAP as shown in the log files and specified in the saml-nameid.properties
file.

Mike
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160831/fd16b43c/attachment-0001.html>


More information about the users mailing list