Unencrypted NameID
Robert Lamothe
robert_lamothe at yahoo.com
Tue Feb 2 16:14:10 EST 2016
Greetings Shib Users,
I'm new to shib so my understanding is evolving by the hour, so if I make no sense with my questions please bear with me.
I'm having a problem authenticating to an SP who's service we've contracted. When I had idp.encryption.optional set to false, we got the error
SAML failed to login, Status code is urn:oasis:names:tc:SAML:2.0:status:Responder. When it is supposed to be urn:oasis:names:tc:SAML:2.0:status:Success
When I set idp.encryption.optional to true I can authenticate against my Shib server but then it looks like NameID is coming through encrypted. I see a value that looks like "|AAhzZWNyZXQyM0d3l9SkgTcyhW0EIFydZAtaItLmybSzB0mgY1T+cxMB+mJ0BlUBwc96n6RtkPb2HMuWxucuUTEKziIJj6lXr4U6dx8G5TwsYIJ3ACiuowj8KgiW07voQ7Xy948b2DZDmyBhw1Cojjw="
Based on some reading I've done it appears that NameID is encrypted if end to end encryption can't be assured, so it looks like I have 2 possible solutions, one is to figure out how to insure end to end is encrypted, the other would be to set it so I can send NameID in clear text.
I'm at a loss how to do either, can someone guide me?
Thanks-Bob
--
Bob Lamothe
robert_lamothe at yahoo.com
KB1BOB
603-918-6336
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160202/5f040606/attachment.html>
More information about the users
mailing list