convert legacy NameID to current

Peter Schober peter.schober at univie.ac.at
Thu Aug 8 17:10:03 EDT 2019


* sherrera <sherrera at bradley.edu> [2019-08-08 22:45]:
> The way I was able to see what was being released is at the sign in page, it
> lists what attributes it will release to the SP. I verified that against a
> saml plugin for my browser and in the log file idp-process.log.

None of these methods would show the NameID. (Maybe the browser
plugin would but only if the SP receives unencrypted assertions from
you.)
The one I mentioned and which is easy and reliable does.
Simple choice for me but YMMV.

> I'm releasing 3 attributes but only see 2 of them. Here is my
> attribute-filter.xml entry. I believe I am requesting the mail
> attribute correctly.

There's no magic in releasing the mail attribute. Either the entityID
matches it it doesn't.

As for the NameID there's the aacli. If that doesn't show it going out
as NameID (it won't, from your WARN log message) you'll have to
increase logging to see what's going on.

-peter


More information about the users mailing list