v3.2 - unsupportable identifier -Name ID

Ramaiah, Vanna G. ramaiah at musc.edu
Tue Feb 21 10:06:28 EST 2017


There was no upgrade. It was fresh installation of V3.2. Commenting out idp.nameid.saml2.legacyGenerator helped the NameID specified.
I am still getting errors for NameID unspecified ones. Any idea?


-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Andrew Morgan
Sent: Monday, February 20, 2017 6:52 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: v3.2 - unsupportable identifier -Name ID



On Mon, 20 Feb 2017, Ramaiah, Vanna G. wrote:

> I am working on upgrading to v3.2. All SPs that were using NameIds 
> (specified and unspecified) are throwing error even if a format is 
> specified. Could you please tell me how to fix this and also point me 
> to a document that has valid list of NameId format.
> nameFormat="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"
> nameFormat="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"

In-place upgrades should be seamless.  Assuming you are upgrading from IDP v2, did you disable the legacy NameID generation in
saml-nameid.properties:

idp.nameid.saml2.legacyGenerator= shibboleth.LegacySAML2NameIDGenerator

I'm trying to figure out if you are using the legacy v2 NameID stuff or the new v3 generation.

Thanks,
        Andy
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net







More information about the users mailing list