urn:oasis:names:tc:SAML:2.0:nameid-format:persistent

Andrew Jason Morgan morgan at oregonstate.edu
Wed Aug 5 23:36:34 UTC 2020


You probably need to use an activation condition in conf/saml-nameid.xml, but ...

Why not tell the vendor you're happy to release 'mail' as 'urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress' instead?  An email address does not meet the requirements of the SAML spec for a persistent NameID.

Thanks,

Andy Morgan
Identity & Access Management
Oregon State University

________________________________
From: users <users-bounces at shibboleth.net> on behalf of Joshua Brodie <josbrodie at gmail.com>
Sent: Wednesday, August 5, 2020 4:23 PM
To: users <users at shibboleth.net>
Subject: urn:oasis:names:tc:SAML:2.0:nameid-format:persistent

Hi List:

Been away for few weeks on another project and my brain is back on SAML.

In v3.4.7, we have the following:

idp.persistentId.generator = shibboleth.StoredPersistentIdGenerator

Where it generates the eduPersonTargetedID based on a seed/salt pair.

But we now need to make the value sent under 'urn:oasis:names:tc:SAML:2.0:nameid-format:persistent'  dynamic. A SP is requesting 'mail' as 'urn:oasis:names:tc:SAML:2.0:nameid-format:persistent'.


I thought I could override the source attribute via 'saml-nameid.xml' -- but can't seem to. urn:oasis:names:tc:SAML:2.0:nameid-format:persistent always resorts to the eduPersonTargetedID value.

I am certain I am missing something. But not so sure where.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20200805/657a9b63/attachment.htm>


More information about the users mailing list