IDP 5.1.1 - adding SP metadata file to IDP without certificate

Saadallah Itani sitani at aub.edu.lb
Tue Jun 25 12:53:59 UTC 2024


Hi Scott,

Is it possible for the IDP to generate nameid that is equal to the objectguid 
attribute for a specific SP (this SP) as other SPs might expect different 
value for nameid.


Regards,
Saad
ext 2229

-----Original Message-----
From: Cantor, Scott <cantor.2 at osu.edu>
Sent: Tuesday, June 25, 2024 3:43 PM
To: Saadallah Itani <sitani at aub.edu.lb>; Shib Users <users at shibboleth.net>
Subject: Re: IDP 5.1.1 - adding SP metadata file to IDP without certificate

> Thanks for replying, however if I do not add any certificate to
> the metadata  file it will not correctly redirect to the login
> page.

I'm simply stating that a certificate has nothing to do with this unless the 
IdP is just not told to allow for no encryption, which is logged.

> The below is an extract of the saml tracer that shows ADFS is
> sending  objectguid as nameid to policytech, how can I
> replicate this setup on IDP?

You shouldn't because that's a terrible idea, but NameID generation based on a 
resolved attribute is covered by the documentation.

-- Scott


-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 7274 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20240625/c260b3a2/attachment.p7s>


More information about the users mailing list