InvalidNameIDPolicy occurs when using multi-factor authentication
Rod Widdowson
rdw at steadingsoftware.com
Sun Feb 3 02:21:48 EST 2019
Did you chase up why this
> [INFO]net.shibboleth.idp.saml.nameid.impl.AttributeSourcedSAML2NameIDGenerator:227] - Attribute sources [ImmutableID] did not produce a usable identifier
Happened? You’ll need a log of the attribute resolution. My guess would be that the principal is different in the two cases and when you present that to LDAP it doesn’t resolve...
Rod
More information about the users
mailing list