PersistentNameIDGenerationConfiguration: Type 4 UUID

Hugo Slavia hugoslavia101 at gmail.com
Fri Jan 26 03:01:13 EST 2018


The following is in the attribute-resolver........I can't fathom yet what
could be awry.......anything to watch out for in idp-process.log (debug)?

<resolver:DataConnector id="myStoredId" xsi:type="dc:StoredId"
generatedAttributeID="persistentID"
sourceAttributeID="%{idp.persistentId.sourceAttribute}"
salt="%{idp.persistentId.salt}" queryTimeout="PT5S" transactionRetries="5"
retryableErrors="72000 23000">
                <resolver:Dependency ref="%{idp.persistentId.sourceAttribute}"
/>
                <dc:BeanManagedConnection>OracleDataSource</dc:
BeanManagedConnection>
            </resolver:DataConnector>

On Thu, Jan 25, 2018 at 6:05 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> On 1/25/18, 8:55 PM, "users on behalf of Hugo Slavia" <
> users-bounces at shibboleth.net on behalf of hugoslavia101 at gmail.com> wrote:
>
> >  Uncommenting 'idp.persistentId.generator' --- creates HASH for 1st
> PERSISTENTID (for that user/SP).  {expected UUID as
> > 'idp.persistentId.computed' is empty property}.
>
> That would not happen, so in these cases I fall back to my "facts are not
> as presented" response that generally leads to "oh, right, X wasn't what I
> thought it was".
>
> It has to still be injecting the hash strategy into the stored plugin, and
> the code doesn't do that if it's told not to.
>
> Offhand I might guess the attribute resolver is still configured to do all
> this the old way and these settings aren't being used.
>
> -- Scott
>
>
>
>
>
> --
> For Consortium Member technical support, see https://wiki.shibboleth.net/
> confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20180126/3177a616/attachment.html>


More information about the users mailing list