Persistent ID via eduPersonTargetedID in IdP 2.4.4
Kylie Lunghusen
kylie.lunghusen at rmit.edu.au
Mon Jul 3 22:13:35 EDT 2017
Thanks, Scott. Sorry I wasn't clear. It was "ad:Simple" that I tried when I
broke the IdP in Dev.
--
Kylie Lunghusen
Technical Tools Administrator, University Operations
Information Technology Services, RMIT University
On 3 July 2017 at 23:44, Cantor, Scott <cantor.2 at osu.edu> wrote:
> > The closest thing my research found suggested editing attribute resolver
> to
> > change the ePTID AttributeDefinition's xsi:type from "ad:SAML2NameID" to
> > "Simple", but when I deployed that to Dev environment, it wouldn't start
> > Shibboleth, and gave "Attribute 'nameIdFormat' is not allowed to appear
> in
> > element 'resolver:AttributeDefinition'." in idp-process.log.
>
> Generating a persistentID in the Subject involves the StringSAML2NameID
> encoder layered on top of the result of one of the two data connectors
> (computed or stored), but your problem is probably the use of the
> SAML2NameID attribute definition. You want ad:Simple instead.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170704/3f41b666/attachment.html>
More information about the users
mailing list