InvalidNameIDPolicy occurs when using multi-factor authentication

Rod Widdowson rdw at steadingsoftware.com
Sun Feb 3 02:21:48 EST 2019


Did you chase up why this

> [INFO]net.shibboleth.idp.saml.nameid.impl.AttributeSourcedSAML2NameIDGenerator:227] - Attribute sources [ImmutableID] did not produce a usable identifier

Happened?  You’ll need a log of the attribute resolution.  My guess would be that the principal is different in the two cases and when you present that to LDAP it doesn’t resolve...

Rod


More information about the users mailing list