nameID format & encryption for GAE integration

IAM David Bantz dabantz at alaska.edu
Thu Jun 27 19:07:22 EDT 2019


The helpful Shibb wiki page Google Apps for Education
<https://wiki.shibboleth.net/confluence/pages/editpage.action?pageId=24773323>
indicates
Google needs nameID formatted as email:
>
> "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"

but in my first attempt to integrate a "proof of concept" GAE domain, the
incoming SAML request has

>  <samlp:NameIDPolicy AllowCreate="true" Format=

"urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"/>


What does experience indicate is correct? Or is this an example of SC's
experience that vendors may claim to need a specific format, but really do
not?

That page also indicates using configuring no encryption in
relying-party.xml. Isn't that redundant if there is no certificate in
metadata?

David Bantz
UA OIT IAM
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190627/ac57f384/attachment.html>


More information about the users mailing list