Idp3 + GAFE

Jukka Hakosalo jhakosal at gmail.com
Thu Jun 9 09:07:54 EDT 2016


Hi,

We have an Idp3. It's working mostly fine. There are problems with Google's
GAFE.

In relying-party.xml we have:
----------------------------
        <bean parent="RelyingPartyByName"
c:relyingPartyIds="google.com">

            <property
name="profileConfigurations">

<list>
                    <bean parent="SAML2.SSO"

p:nameIDFormatPrecedence="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"

                         p:encryptAssertions="false" />
                         p:postAuthenticationFlows="#{ {'context-check'}
}"/>
                </list>
            </property>
        </bean>
-------------------------

Attribute-filter and attribute-resolver are similar to old idp2. GAFE
worked before.

After login GAFE says:
-----------------------
This account cannot be accessed because we could not parse the login
request.


idp-process.log:
-----------------------------------
WARN
[org.opensaml.saml.common.profile.logic.MetadataNameIdentifierFormatStrategy:75]
- Ignoring NameIDFormat metadata that includes the 'unspecified' format

Where should I start to find the solution?

Thanks,
Jukka
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160609/c8d9777a/attachment.html>


More information about the users mailing list