No candidate NameID formats
Peter Schober
peter.schober at univie.ac.at
Tue Jan 3 13:24:46 UTC 2023
* Rod Widdowson <rdw at steadingsoftware.com> [2023-01-03 12:10]:
> This doesn't help you, but that reflects what the code is doing -
> the allowable NameIDs consist of the _intersection_ of the set
> specified in the profile and the set specified in the metadata.
Thanks, Rod.
That behaviour makes sense assuming the published metadata was
complete and that the IDP merely wanted to make a different choice out
of the formats listed -- not use a different format altogether.
(Admittedly the XML attribute is called nameIDFormatPrecedence,
probably hinting at that.)
Also thanks for the pointer to the metadata filter that would allow to
modify the metadata in a way to make the override work as we would
have needed it to here.
In this case I was able to get the metadata amended at the source,
avoiding any such changes for our IDPs -- which is of course hugely
preferrable. (Thanks to SWITCHaai their help!)
-peter
More information about the users
mailing list