Weird issue with SAML-NAMEID.xml

Melvin Lasky melvin.lasky at manhattan.edu
Fri Jun 3 18:34:41 UTC 2022


Scott,
	You are the man! All fixed.

Thanks

Mel


Melvin Lasky
Associate Director of Enterprise Architecture





Riverdale, NY 10471
Phone: 718-862-7410
melvin.lasky at manhattan.edu
www.manhattan.edu


> On Jun 3, 2022, at 2:04 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> 
> You don't do this by touching anything but metadata. Add the relevant NameIDFormat to the SP's metadata or add a filter to add it. Done.
> 
> Do NOT create one-off NameID generator beans and do not use activation conditions to control them. Just because it's possible doesn't mean you should ever do it. It's there as an absolute last resort.
> 
> The documentation does not in any way suggest doing this, so I don't know why people are doing it or what would lead somebody to think it makes sense, but it's analagous to creating an LDAP plugin that changes what attribute values are served up for a fixed attribute type based on the bind DN. Nobody would even think of doing that, and this is the same.
> 
> If you create an email Format generator based on the filtered value of mail (or whatever attribute you use), then you need not worry about anything but releasing the relevant attribute to the SP and making sure its metadata stipulates the right Format.
> 
> -- Scott
> 
> 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220603/f9b70203/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 1.jpeg
Type: image/jpeg
Size: 3547 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20220603/f9b70203/attachment.jpeg>


More information about the users mailing list