v2->v3 upgrade, google apps

Cantor, Scott cantor.2 at osu.edu
Wed Jul 13 21:17:44 EDT 2016


On 7/13/16, 9:03 PM, "users on behalf of Baron Fujimoto" <users-bounces at shibboleth.net on behalf of baron at hawaii.edu> wrote:

> However, it's also the case that reusing the original post-upgrade
> metadata and relying-party.xml[*] results in the "Invalid Email" error
> when testing using the /etc/hosts method.

I can't explain that, but without seeing it in action, there's not much I can say. All I know is that it works (we know this because you're using the same code below). The old V2 config *had* to have a format precedence set to "unspecified", and if it did, V3 should be using it if it's there post-upgrade.
 
> Maybe this is is still "wrong", but it seems to be working.

Nothing wrong, though if it's an email address, that's one of the very few types of NameIDs that actually has a SAML-defined Format. But Google doesn't care so it really is immaterial.

My configuration is a hybrid. I have updated my relying-party usage, but I'm still generating NameIDs via the attribute resolver and its encoders. Mixing and matching works fine. Eventually I'll get around to moving those over to the saml-nameid file, but it's just not that important.

-- Scott




More information about the users mailing list