Updated Adobe "IDP" (SP) config results in scrambled nameid
Simon Lundström
simlu at su.se
Tue Oct 20 08:15:06 UTC 2020
Side note: While the new Adobe SP doesn't specify it in their metadata
using "urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified" NameID
still works for the new SP like it did for their old SP.
Sorry Scott for "promoting"
urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified ; P
BR,
- Simon
On Tue, 2020-10-20 at 02:17:45 +0200, Ben Poliakoff wrote:
>I read the earlier thread on this list "Notice from Adobe about IdP SHA-1 certificates", and was following the instructions (https://helpx.adobe.com/enterprise/admin-guide.html/enterprise/using/set-up-identity.ug.html#migrateesaml) today. It seemed essentially to be like adding a new SP (loaded the new SP metadata, set up attribute release policies identical to the ones I used with the existing Adobe config).
>
>When I get to the testing part it seems that something's behaving differently with the encoding of the nameid. We've been using the email based nameid that Adobe had requested, and with the existing SP config that seems to work just fine. I can see the nameid-as-email address being released in the logs. But when I test the new Adobe SP that nameid (which Adobe uses as the username) is scrambled.
>
>With the current SP configuration "username at reed.edu<mailto:username at reed.edu>" is released, when I test the new configuration I can see in the logs that it's releasing a 32 character alphanumeric string. And indeed the test result page reports that string as my username.
>
>I can only imagine I'm missing something fairly obvious, but I've configured dozens of SPs before and never run into an issue like this. Any suggestions would be greatly appreciated!
>
>Ben
>
>--
>For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
>To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list