Interop shibb SP - Google SAML IdP

Peter Schober peter.schober at univie.ac.at
Thu Jun 30 05:05:30 EDT 2016


Thanks for sharing, just one question for clarification:

* Rich Graves <rgraves at carleton.edu> [2016-06-30 01:45]:
> - As expected they send
>  <md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</md:NameIDFormat>

But below you write:

> - The attribute and NameID formats are unspecified. The below
> in attribute-map.xml "worked" for me. Please let me know if any of this is
> wrong or insecure. They don't appear to scope email address in any way so
> the recent Office 365 "SAML" vulnerability likely applies to sites that
> trust the Google IdP.
>     <Attribute name="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
> id="google-id">
>         <AttributeDecoder xsi:type="NameIDAttributeDecoder"
> formatter="$Name" defaultQualifiers="true"/>
>     </Attribute>

So which NameID is it? email or unspecified?

Cheers,
-peter


More information about the users mailing list