NameID Format/Policy help
Peter Schober
peter.schober at univie.ac.at
Wed Aug 21 10:02:50 UTC 2024
Paul B. Henson via users <users at shibboleth.net> [2024-08-21 01:10 CEST]:
> So basically you are telling the SP they can ask for it, and then
> you can't provide it, which isn't really their fault…
Not so sure about that, given that the NameID they're asking for is
for SAML1 and the protocol they're using is SAML 2.
But then how would they know what that URI is/means...
That's the first time I've heard of an SP looking at NameIDFormats as
announced by the IDP, I think. Which would explain why this hasn't
been an issue before. Which also means that it's likely safe to remove
both formats from your metadata -- whatever that'll do to that SP, then.
FWIW, my own IDPs and those within our local federation have been
SAML1-free for many, many years. Unless that IDP actually needs to
support SAML1 SPs (a mere 19 years after SAML 2.0 was published) that
format should be removed from metadata, no doubt. And probably even if
the OP still had SAML 1 SPs (as those very likely won't be checking
the OP's IDP's metadata for supported NameID formats.)
I've also not listed 'transient' in metadata and never notived a
difference. So IMO that could be removed as well.
-peter
More information about the users
mailing list