configure multiple name formats in SP attribute extractor

Prasanth Kumar K kprasanthk at
Wed Jan 27 14:20:22 UTC 2021

In our Shib SP we try to extract and decode the attribute "memberOf" from
multiple IdPs during assertion. since our SP supported by multiple IdPs.
The problem, we are facing each IdP sends a different nameFormat.

IdP1  sending below saml response
<Attribute Name="memberOf">

IdP2 sending below saml reponse
<saml:Attribute Name="memberOf"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic" >
<saml:AttributeValue xsi:type="xs:string">eln</saml:AttributeValue>

In our shib sp we have configured like below to extract  "memberOf "

<Attribute name="memberOf"
<AttributeDecoder xsi:type="StringAttributeDecoder" caseSensitive="false"/>

The above sp config doesn't seems to be working when IdP2 sends

Also, reading shib doc says expect
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic" from Sp
side. refer here

How to configure SP's attribute extractor for multiple nameformats of the
same attribute? so that, we can able to extract and decode the attribute
during saml assertions.

Thank you,
Prasanth K
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <>

More information about the users mailing list