Hi,<div><br></div><div>I think NameID is required if you want Single Logout.</div><div>It is required in the LogoutRequest.</div><div><br></div><div>Y.<br><br><div class="gmail_quote">On Wed, Jul 25, 2012 at 9:52 PM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="im">On 7/25/12 3:24 PM, &quot;Martin B. Smith&quot; &lt;<a href="mailto:smithmb@ufl.edu">smithmb@ufl.edu</a>&gt; wrote:<br>

&gt;<br>
&gt;I&#39;m looking at the difference between sending a SAML2 Name Identifier (a<br>
&gt;persistent one) as part of the Subject in an assertion and/or as part of<br>
&gt;the AttributeStatement of an assertion.<br>
<br>
</div>Most implementations can&#39;t handle a complex attribute value like a NameID.<br>
Using the subject is better for interoperability if the data can&#39;t be<br>
represented without XML. That particular NameID Format has no defined<br>
representation other than as a NameID element.<br>
<div class="im"><br>
&gt;I don&#39;t have a sense as to whether it makes sense to send in both<br>
&gt;subject and attributestatement, or whether one should suffice?<br>
<br>
</div>I suppose you can cover all your bases with both, but I don&#39;t know of<br>
anything that would fail to handle the former but would handle the latter.<br>
I&#39;m sure something does.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>