relying party rule question
Mike Flynn
shibbolethlynda at yahoo.com
Tue Apr 25 22:00:04 EDT 2017
Thanks Scott
On Tuesday, April 25, 2017 5:06 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
On 4/25/17, 4:15 PM, "users on behalf of Mike Flynn" <users-bounces at shibboleth.net on behalf of shibbolethlynda at yahoo.com> wrote:
> I have a customer that is telling me this:
>
> you need to change the supplier initiated SAML request to use:
> <samlp:NameIDPolicy AllowCreate="true" Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress" />
If they want to send you that Format, which is dumb to begin with, they're more than capable of doing it themselves.
> I have about 2000 IDPs connected to me and I do not want to change anything to affect those folks. Is it possible to set a relying
> party rule or something to give these folks what they are asking for?
https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPRelyingPartySettings
As of 2.6 you can set NameIDFormat in one. But if you screw it up, you can break pretty much any IdP, so it's not something to mess with in production without testing it first. NameIDPolicy has mandatory semantics in SAML, an IdP can't ignore it.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170426/9723a844/attachment.html>
More information about the users
mailing list