Issue with urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified

Nate Klingenstein ndk at signet.id
Tue Oct 16 16:20:26 EDT 2018


Hamsa,

 There is a lot of configuration there that you probably don't need.  If all you want to do is send an attribute as an unspecified NameIDFormat to a particular provider, define that NameIDFormat naming the attributes that you would like to populate it with and add an ActivationCondition that limits its release to that provider.  You should be able to fit all of that in a few lines of saml-nameid.xml.  A basic example might look like:
     <bean parent="shibboleth.SAML2AttributeSourcedGenerator"
              p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
              p:attributeSourceIds="#{ {'username'} }">
        <property name="activationCondition">
            <bean parent="shibboleth.Conditions.RelyingPartyId" c:candidates="#{{'XXXXXXXXXXXXXXX'}}" />
        </property>
    </bean>
 You will also need to explicitly force the use of unspecified NameID's for that relying party in relying-party.xml.
 2018-10-16 10:25:00,979 - WARN
[org.opensaml.saml.common.profile.logic.MetadataNameIdentifierFormatStrategy:?]
- Ignoring NameIDFormat metadata that includes the 'unspecified' format 
 https://wiki.shibboleth.net/confluence/display/IDP30/CustomNameIDGenerationConfiguration#CustomNameIDGenerationConfiguration-Dealingwith%22Unspecified%22
 <bean parent="RelyingPartyByName" c:relyingPartyIds="XXXXXXXXXXXXX">
    <property name="profileConfigurations">
        <list>
            <bean parent="SAML2.SSO" p:encryptAssertions="false" p:assertionLifetime="PT60M" p:securityConfigurationref="XXXXXXXXX"
                p:nameIDFormatPrecedence="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified" />
        </list>
    </property>
</bean>
 You will almost certainly want to disable the legacy name generators, though it should be uninvolved regardless in this situation.
 Take care,
Nate.
-----Original message-----
From: Hamsa
Sent: Tuesday, October 16 2018, 12:32 pm
To: users at shibboleth.net
Subject: Issue with urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
 
Hi,
I am getting Policy checking disabled for NameIDPolicy with Format
urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified though I have defined
my bean as below in my relying-party.xml file and I am using activation
condition

<bean id="MyBean" parent="RelyingParty">
          <property name="activationCondition" 
                          ref="ServiceNowCondition" /> 
         <property name="responderId" value="XXXXXXXXXX" />
			<property name="profileConfigurations">
				<list>
					<bean parent="SAML2.SSO" p:assertionLifetime="PT60M"
						p:encryptAssertions="false" p:securityConfigurationref="XXXXXXXXX"
					
p:nameIDFormatPrecedence="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
/>
					
				</list>
			</property>

        </bean>

And my SP metadata has 
<NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</NameIDFormat>

And my saml-nameid.xml

<bean parent="shibboleth.SAML2AttributeSourcedGenerator"
p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
p:attributeSourceIds="#{ {'username'} }">
			<property name="activationCondition">
				<bean parent="shibboleth.Conditions.RelyingPartyId"
					c:candidates="#{{
						<!-- my SP entityIDs -->
				}}" />
			</property>
		</bean>

And i have enabled 
idp.nameid.saml2.legacyGenerator = shibboleth.LegacySAML2NameIDGenerator
idp.nameid.saml1.legacyGenerator =
shibboleth.LegacySAML1NameIdentifierGenerator

Please someone guide me in right direction? I have following in my Log,

2018-10-16 10:25:00,978  - DEBUG
[org.opensaml.saml.saml2.profile.impl.AddNameIDToSubjects:?] - Profile

Action AddNameIDToSubjects: Attempting to add NameID to outgoing Assertion
Subjects
2018-10-16 10:25:00,979 -DEBUG
[org.opensaml.saml.common.profile.logic.AbstractNameIDPolicyPredicate:?] -
Policy checking disabled for NameIDPolicy with Format
urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
2018-10-16 10:25:00,979 - WARN
[org.opensaml.saml.common.profile.logic.MetadataNameIdentifierFormatStrategy:?]
- Ignoring NameIDFormat metadata that includes the 'unspecified' format
2018-10-16 10:25:00,982 -   DEBUG
[net.shibboleth.idp.saml.profile.logic.DefaultNameIdentifierFormatStrategy:?]
- Configuration specifies the following formats: []
2018-10-16 10:25:00,982 - DEBUG
[net.shibboleth.idp.saml.profile.logic.DefaultNameIdentifierFormatStrategy:?]
- No formats specified in configuration or in metadata, returning default
2018-10-16 10:25:00,982 -  DEBUG
[org.opensaml.saml.saml2.profile.impl.AddNameIDToSubjects:?] - Profile

Action AddNameIDToSubjects: Candidate NameID formats:
[urn:oasis:names:tc:SAML:2.0:nameid-format:transient]
2018-10-16 10:25:00,982 - DEBUG
[org.opensaml.saml.saml2.profile.impl.AddNameIDToSubjects:?] - Profile

Action AddNameIDToSubjects: Trying to generate NameID with Format
urn:oasis:names:tc:SAML:2.0:nameid-format:transient
2018-10-16 10:25:00,982 -DEBUG
[org.opensaml.saml.common.profile.impl.ChainingNameIdentifierGenerator:?] -
Trying to generate identifier with Format
urn:oasis:names:tc:SAML:2.0:nameid-format:transient



--
Sent from: http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html <http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html> 
-- 
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net <mailto:users-unsubscribe at shibboleth.net> 


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20181016/b0412299/attachment.html>


More information about the users mailing list