PersistentNameIDGenerationConfiguration: Type 4 UUID
Hugo Slavia
hugoslavia101 at gmail.com
Fri Jan 26 03:01:13 EST 2018
The following is in the attribute-resolver........I can't fathom yet what
could be awry.......anything to watch out for in idp-process.log (debug)?
<resolver:DataConnector id="myStoredId" xsi:type="dc:StoredId"
generatedAttributeID="persistentID"
sourceAttributeID="%{idp.persistentId.sourceAttribute}"
salt="%{idp.persistentId.salt}" queryTimeout="PT5S" transactionRetries="5"
retryableErrors="72000 23000">
<resolver:Dependency ref="%{idp.persistentId.sourceAttribute}"
/>
<dc:BeanManagedConnection>OracleDataSource</dc:
BeanManagedConnection>
</resolver:DataConnector>
On Thu, Jan 25, 2018 at 6:05 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 1/25/18, 8:55 PM, "users on behalf of Hugo Slavia" <
> users-bounces at shibboleth.net on behalf of hugoslavia101 at gmail.com> wrote:
>
> > Uncommenting 'idp.persistentId.generator' --- creates HASH for 1st
> PERSISTENTID (for that user/SP). {expected UUID as
> > 'idp.persistentId.computed' is empty property}.
>
> That would not happen, so in these cases I fall back to my "facts are not
> as presented" response that generally leads to "oh, right, X wasn't what I
> thought it was".
>
> It has to still be injecting the hash strategy into the stored plugin, and
> the code doesn't do that if it's told not to.
>
> Offhand I might guess the attribute resolver is still configured to do all
> this the old way and these settings aren't being used.
>
> -- Scott
>
>
>
>
>
> --
> For Consortium Member technical support, see https://wiki.shibboleth.net/
> confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20180126/3177a616/attachment.html>
More information about the users
mailing list