Error in the idp-process.log

Cantor, Scott cantor.2 at osu.edu
Mon Jul 24 16:47:52 EDT 2017


On 7/21/17, 11:05 AM, "users on behalf of Cantor, Scott" <users-bounces at shibboleth.net on behalf of cantor.2 at osu.edu> wrote:

> Ok, first conclusion: your original question:

And my secondary points after having some time to review the code and the configurations posted:

You cannot be getting NameIDs in the Subject element with a configuration whose NameID Generation service layer is failing and reporting errors of the type posted.

That is also consistent with the fact that the configuration posted with legacy connectors inside the Attribute Resolver is not even trying to do that. It's generating the deprecated eduPersonTargetedID SAML Attribute [1].

That is not the same thing as a SAML persistent NameID syntactically and doesn't depend on the NameID generation layer in the IdP, which is why it's "working". It's just not generating any NameIDs, and never was to begin with.

I can't tell you what your services are depending on. When you have undocumented systems handed off, that loss of knowledge is obviously a serious problem. If you knew which services were relying on the Attribute, then it would be possible to reconfigure a test system to avoid all the deprecated pieces and see if things still work if it's passed in the Subject.

-- Scott

[1] https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPTargetedID




More information about the users mailing list