v3.2 - unsupportable identifier -Name ID
Ramaiah, Vanna G.
ramaiah at musc.edu
Tue Feb 21 10:06:28 EST 2017
There was no upgrade. It was fresh installation of V3.2. Commenting out idp.nameid.saml2.legacyGenerator helped the NameID specified.
I am still getting errors for NameID unspecified ones. Any idea?
-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Andrew Morgan
Sent: Monday, February 20, 2017 6:52 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: v3.2 - unsupportable identifier -Name ID
On Mon, 20 Feb 2017, Ramaiah, Vanna G. wrote:
> I am working on upgrading to v3.2. All SPs that were using NameIds
> (specified and unspecified) are throwing error even if a format is
> specified. Could you please tell me how to fix this and also point me
> to a document that has valid list of NameId format.
> nameFormat="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"
> nameFormat="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
In-place upgrades should be seamless. Assuming you are upgrading from IDP v2, did you disable the legacy NameID generation in
saml-nameid.properties:
idp.nameid.saml2.legacyGenerator= shibboleth.LegacySAML2NameIDGenerator
I'm trying to figure out if you are using the legacy v2 NameID stuff or the new v3 generation.
Thanks,
Andy
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list