v2->v3 upgrade, google apps

Takeshi NISHIMURA takeshi at nii.ac.jp
Tue Jul 19 06:51:06 EDT 2016


On 2016/07/14 6:10, Cantor, Scott wrote:
> A legacy config, reused in V3, should produce identical NameID behavior.

We have experienced odd behavior of transient ID with legacy config (*). As it turned out, transient ID was, by default, the exception to legacy config.

Note the instruction below in order to produce the identical behavior of transient ID.
https://wiki.shibboleth.net/confluence/display/IDP30/NameIDGenerationConfiguration
> but that configuration will be superseded by the content of the new saml-nameid.xml file and will fall back to the resolver only as a backstop. You can short-circuit the new functionality by commenting out the content of the two generator list beans and leaving them empty.

(*) - To be explained in detail, the cause was a misconfiguration of metadata. In our case, an SP metadata contained only urn:mace:shibboleth:1.0:nameIdentifier as <NameIDFormat>, so v3 did not send any transient ID during SAML 2.0 SSO.

Regards,
Takeshi


More information about the users mailing list