IdPv3 and Hathitrust: how to resolve and release SAML V2.0 persistent NameID

Wang, Lihua lwang2 at gc.cuny.edu
Fri Jul 7 15:18:52 EDT 2017


Hi Shibboleth community users,

We are trying to set up a shibboleth IdP server for hathitrust.

We have joined incommon federation with a test IdP to explore attribute resolution and release to the service provider.

We can successfully resolve and release eduPersonScopedAffiliation, displayName and eduPersonEntitlement, but we have not been able resolve or release SAML V2.0 persistent NameID.

For SAML2 persistentname ID, we uncommented the following 2 lines in saml-named.properties:

idp.persistentId.sourceAttribute = sAMAccountName
idp.persistentId.salt = oursecretestring

as well as the SAML2PersistentGenerator in saml-named.xml:

<ref bean="shibboleth.SAML2PersistentGenerator" />

But what do we need to do to resolve the persistent NameID and release it to a service provider?

I have searched and read extensively but have not been able to find an answer. There has been inconsistent or non-definitive information (e.g. adding some RelyingPartyByName stanza to relyingparty.xml, or tinkering with conf/c14n/subject-c14n.xml file ), which we tested but without success. Hathitrust workgroup directed me to this mailing list to seek help.

We are using Shibboleth IdP 3.3.1.

Thanks in advance for your advice/guidance.

Best regards,

Lihua Wang
Lead Linux Systems Admin
CUNY Graduate Center

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170707/d27bc337/attachment.html>


More information about the users mailing list