Persistent NameID format with an attribute as NameID value
ℂarl Waldbieser
waldbiec at lafayette.edu
Wed Aug 13 19:11:07 UTC 2025
Keith,
We did an SSO setup with the National Student Clearinghouse recently
(MyHub), and the NameID that you send doesn't show up anywhere as far as I
can tell. We send our opaque student ID.
Thanks,
Carl Waldbieser
ITS
Lafayette College
On Wed, Aug 13, 2025 at 2:48 PM Wessel, Keith via users <
users at shibboleth.net> wrote:
> Hi, all,
>
> It pained me to write that subject line.
>
> We're updating to a newer SSO integration with the National Student
> Clearinghouse. They tell me they need a persistent Name ID. That is, the
> name ID format needs to be set to
> urn:oasis:names:tc:SAML:2.0:nameid-format:persistent. But they also tell me
> that the value we send will be user-visible.
>
> While I'm tempted to say that we'll just send them the usual pairwise
> persistent ID that, while not pretty, at least works out of the box, I
> figured I'd at least explore doing what our registrar's office wanted.
>
> How would I get the IdP to use an attribute-sourced Name ID generator that
> sends an attribute as the Name ID but with a format of persistent?
>
> Thanks,
> Keith
>
> --
> For Consortium Member technical support, see
> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250813/3af02f32/attachment.htm>
More information about the users
mailing list