nameID format & encryption for GAE integration
IAM David Bantz
dabantz at alaska.edu
Thu Jun 27 19:07:22 EDT 2019
The helpful Shibb wiki page Google Apps for Education
<https://wiki.shibboleth.net/confluence/pages/editpage.action?pageId=24773323>
indicates
Google needs nameID formatted as email:
>
> "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"
but in my first attempt to integrate a "proof of concept" GAE domain, the
incoming SAML request has
> <samlp:NameIDPolicy AllowCreate="true" Format=
"urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"/>
What does experience indicate is correct? Or is this an example of SC's
experience that vendors may claim to need a specific format, but really do
not?
That page also indicates using configuring no encryption in
relying-party.xml. Isn't that redundant if there is no certificate in
metadata?
David Bantz
UA OIT IAM
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190627/ac57f384/attachment.html>
More information about the users
mailing list