Shib IdP Proxying to another IdP help
Cantor, Scott
cantor.2 at osu.edu
Tue Feb 22 23:56:29 UTC 2022
I added a few notes to the relevant documentation pages that highlight the issues with NameFormat defaults and, less helpfully to anybody now, added a comment to all the default rule files about it.
-- Scott
On 2/22/22, 6:19 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
On 2/22/22, 5:56 PM, "users on behalf of Brent Goebel" <users-bounces at shibboleth.net on behalf of Brent.Goebel at du.edu> wrote:
> Going off your example of givenName. We are using the URN:OID. See the entry for it in our resolver below.
With no NameFormat constant in the Attribute element, so that is not a match. SAML naming is broken because a whole lot of people then and now refuse to accept URI naming of anything. It is not the default in SAML, but it is the default in Shibboleth, so the NameFormat constant has to be present and set properly or the default rules don't apply. You are using a NameFormat of "urn.....:unspecified", implied by its absence.
More information about the users
mailing list