eduPersonTargetedID not being sent as persistent

Mak, Steve makst at upenn.edu
Wed Jan 8 11:35:38 EST 2020


If this is through InCommon, EverFi does not seem to declare a NameIDFormat preference which will resolve to "unspecified" to the IdP logic without some additional work.

You would need to set a relying party override for this entity ID to force the NameID Format to a persistent type, and combine that with a properly defined generated nameid with persistent format sourced from your TargetedID attribute and a filter release that enables the attribute.

That should allow the IdP to "pick" the persistent NameID from the pool of attributes.

On 1/8/20, 09:43, "users on behalf of mhc-shib-admin" <users-bounces at shibboleth.net on behalf of cswoods at mtholyoke.edu> wrote:

Hi Folks-

I am setting up our IDP (v3.3) to work with Everfi. They are asking for a
persistent nameID so I am sending them eduPersonTargetedID. On examining the
SAML, I find this:

<saml2:Subject>
            <saml2:NameID
Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" 
                NameQualifier="https://sso.mtholyoke.edu/idp/shibboleth"
               
SPNameQualifier="https://admin.fifoundry.net/mount_holyoke_college/saml/sp">AAdzZWN....</saml2:NameID>
</saml2:Subject>

I didn't this was possible but as it, apparently is, can anyone suggest how
I can change it to persistent?

Thanks very much.



--
Sent from: https://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html
-- 
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



More information about the users mailing list