NameID Definition and Usage in Shib IDP 4

Cantor, Scott cantor.2 at
Thu Jan 7 23:23:54 UTC 2021

On 1/7/21, 6:15 PM, "users on behalf of prasanna cg via users" <users-bounces at on behalf of users at> wrote:

>    Thanks Scott. I agree with your point. Unspecified in my example was just for illustration. The behavior is same
> regardless of the NameID format used. I am glad that I am doing it correct. And this is not an issue per se. But the
> question came out of curiosity to know if I am doing anything incorrect as I noticed this difference between v3 and v4. 

No. If you cared about it, the workaround is to define a custom attribute layered on top that had no default or explicit Attribute encoding rule defined and source the NameID from that instead of the original.

Or reverse it and define the standard one on top of the non-standard one. Either way it's an extra attribute definition to maintain to basically solve a non-problem.

-- Scott

