nameID format & encryption for GAE integration
Cantor, Scott
cantor.2 at osu.edu
Thu Jun 27 19:15:10 EDT 2019
On 6/27/19, 7:07 PM, "users on behalf of IAM David Bantz" <users-bounces at shibboleth.net on behalf of dabantz at alaska.edu> wrote:
> What does experience indicate is correct? Or is this an example of SC's experience that vendors may claim to need a
> specific format, but really do not?
They ignore the Format. Same as most, the value just either matches or doesn't. The documentation is wrong.
Technically their request is correct, they literally are asking for nothing in particular, and the IdP correctly interprets that. The problem is they don't know they're asking for that, so they don't get credit.
> That page also indicates using configuring no encryption in relying-party.xml. Isn't that redundant if there is no
> certificate in metadata?
It's only redundant if you set the idp.encryption.optional property, otherwise the IdP fails unless you explicitly turn off encryption as V2 always did.
-- Scott
More information about the users
mailing list