eduPersonTargetedID not being sent as persistent
Mak, Steve
makst at upenn.edu
Wed Jan 8 11:35:38 EST 2020
If this is through InCommon, EverFi does not seem to declare a NameIDFormat preference which will resolve to "unspecified" to the IdP logic without some additional work.
You would need to set a relying party override for this entity ID to force the NameID Format to a persistent type, and combine that with a properly defined generated nameid with persistent format sourced from your TargetedID attribute and a filter release that enables the attribute.
That should allow the IdP to "pick" the persistent NameID from the pool of attributes.
On 1/8/20, 09:43, "users on behalf of mhc-shib-admin" <users-bounces at shibboleth.net on behalf of cswoods at mtholyoke.edu> wrote:
Hi Folks-
I am setting up our IDP (v3.3) to work with Everfi. They are asking for a
persistent nameID so I am sending them eduPersonTargetedID. On examining the
SAML, I find this:
<saml2:Subject>
<saml2:NameID
Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"
NameQualifier="https://sso.mtholyoke.edu/idp/shibboleth"
SPNameQualifier="https://admin.fifoundry.net/mount_holyoke_college/saml/sp">AAdzZWN....</saml2:NameID>
</saml2:Subject>
I didn't this was possible but as it, apparently is, can anyone suggest how
I can change it to persistent?
Thanks very much.
--
Sent from: https://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html
--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list