I think there might be some misleading communication. For &quot;nameIdentifiers&quot;, I am referring to &quot;urn:mace:shibboleth:1.0:nameIdentifier&quot;, not really the general NameID.<br><br>If I understand correctly, &quot;nameIdentifier&quot; is one type of NameID, there are other types like persistent, transient, and so on. In the IdP metadata, it specifies what types are supported.<br>


<br>What I want to know is, if SP specify transient, it is very clear that the value will be a temporary number. but if SP specify &quot;urn:mace:shibboleth:1.0:nameIdentifier&quot; as the format, SP still doesn&#39;t know what will be the value inside the NameID. SP only knows that this value can represent this user. It can be email address, give name, or what ever. This is defined by IdP. Is that correct? Is there a place that defined what can be put inside the &quot;nameIdentifier&quot; so IdP and SP will follow this rule?<br>


<br>Also it says &quot;urn.....<span style="color:rgb(153,0,0)">shibboleth:1.0</span>:nameIdentifier&quot;, does it mean it only works for SAML1.0? If I send a SAML2.0 AuthnRequest, will IdP return this?<br><br>Best,<br>

Yaowen<br>
<br><br><div class="gmail_quote">On Tue, Jul 31, 2012 at 6:36 PM, Kevin P. Foote <span dir="ltr">&lt;<a href="mailto:kpfoote@iup.edu" target="_blank">kpfoote@iup.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">


<br>
You can encode user name, email etc into a nameID yes. (see links)<br>
<br>
NameID requirements are specified in the metadata. Ex. The SP will<br>
specify what nameIdentifier format it will take / expect.<br>
<br>
I&#39;ve only had to create/send out one or two custom nameIdentifiers.<br>
This usually happens when your dealing with someone elses (non<br>
Shibboleth project) implementation of SAML.<br>
<br>
The list archives also have lots of info/ threads on nameID formats and<br>
how the IdP goes through its selection process before creating the<br>
message.<br>
<div><br>
<br>
------<br>
thanks<br>
  kevin.foote<br>
<br>
On Tue, 31 Jul 2012, Yaowen Tu wrote:<br>
<br>
</div>-&gt; Thanks for your answer.<br>
-&gt;<br>
-&gt; It looks like IdP can put anything they want into the &quot;nameIdentifier&quot; like<br>
-&gt; email, user name, or anything. Is it correct?<br>
-&gt;<br>
-&gt; If so, then how could SP know what will be in the nameIdentifier? Or SP<br>
-&gt; needs to get this information in some other way from IdP?<br>
-&gt;<br>
-&gt;<br>
-&gt; Yaowen<br>
-&gt;<br>
-&gt;<br>
-&gt; On Tue, Jul 31, 2012 at 12:05 PM, Kevin P. Foote &lt;<a href="mailto:kpfoote@iup.edu" target="_blank">kpfoote@iup.edu</a>&gt; wrote:<br>
-&gt;<br>
-&gt; &gt;<br>
-&gt; &gt; You can encode different attributes (data) you have access to into<br>
-&gt; &gt; nameIdentifiers and then<br>
-&gt; &gt; send them out to the various RPs that require or request differing NameID<br>
-&gt; &gt; data..<br>
-&gt; &gt;<br>
-&gt; &gt; <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NameIDAttributes" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/NameIDAttributes</a><br>
-&gt; &gt;<br>
-&gt; &gt;<br>
-&gt; &gt; <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPCustomNameIdentifier" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPCustomNameIdentifier</a><br>
-&gt; &gt;<br>
-&gt; &gt; <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPNameIdentifier" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPNameIdentifier</a><br>
-&gt; &gt;<br>
-&gt; &gt; The IdPs default OOB config is to send the transientId as the NameID .. as<br>
-&gt; &gt; you have found.<br>
-&gt; &gt;<br>
-&gt; &gt; ------<br>
-&gt; &gt; thanks<br>
-&gt; &gt;   kevin.foote<br>
-&gt; &gt;<br>
<div>-&gt; &gt; On Tue, 31 Jul 2012, Yaowen Tu wrote:<br>
-&gt; &gt;<br>
</div>-&gt; &gt; -&gt; Hi,<br>
-&gt; &gt; -&gt;<br>
<div>-&gt; &gt; -&gt; I have installed a sample Shib IdP, it is working in general. I am just<br>
</div>-&gt; &gt; -&gt; trying to explore a little more.<br>
<div>-&gt; &gt; -&gt;<br>
-&gt; &gt; -&gt; &gt;From the IdP metadata, I see this:<br>
</div>-&gt; &gt; -&gt;<br>
<div>-&gt; &gt; &lt;NameIDFormat&gt;urn:mace:shibboleth:1.0:nameIdentifier&lt;/NameIDFormat&gt;<br>
-&gt; &gt; -&gt;<br>
-&gt; &gt; -&gt;<br>
-&gt; &gt; -&gt; So I assume, if an SP send this AuthnRequest, I am supposed to get an<br>
</div>-&gt; &gt; -&gt; nameIdentifier from Assertion:<br>
<div>-&gt; &gt; -&gt;<br>
-&gt; &gt; -&gt; &lt;saml2p:AuthnRequest AssertionConsumerServiceURL=&quot;...&quot; Destination=&quot;<br>
</div>-&gt; &gt; -&gt; <a href="https://localhost/idp/profile/SAML2/Redirect/SSO" target="_blank">https://localhost/idp/profile/SAML2/Redirect/SSO</a>&quot; ID=&quot;<br>
-&gt; &gt; -&gt; _a90ed2b44c1d25860c411e0ab27a9edd&quot;<br>
-&gt; &gt; -&gt; IssueInstant=&quot;2012-07-31T18:21:28.759Z&quot;<br>
-&gt; &gt; -&gt; ProtocolBinding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST&quot;<br>
-&gt; &gt; Version=&quot;<br>
-&gt; &gt; -&gt; 2.0&quot; xmlns:saml2p=&quot;urn:oasis:names:tc:SAML:2.0:protocol&quot;&gt;<br>
-&gt; &gt; -&gt;   &lt;saml2:Issuer xmlns:saml2=&quot;urn:oasis:names:tc:SAML:2.0:assertion&quot;&gt;<br>
-&gt; &gt; -&gt;    .....<br>
-&gt; &gt; -&gt;   &lt;/saml2:Issuer&gt;<br>
<div>-&gt; &gt; -&gt;   &lt;saml2p:NameIDPolicy AllowCreate=&quot;true&quot; Format=&quot;<br>
</div>-&gt; &gt; -&gt; urn:mace:shibboleth:1.0:nameIdentifier&quot;/&gt;<br>
<div>-&gt; &gt; -&gt; &lt;/saml2p:AuthnRequest&gt;<br>
-&gt; &gt; -&gt;<br>
-&gt; &gt; -&gt;<br>
-&gt; &gt; -&gt; In reality, from Idp-process.log, I see this information:<br>
-&gt; &gt; -&gt;<br>
-&gt; &gt; -&gt;<br>
-&gt; &gt; -&gt;<br>
-&gt; &gt; -&gt; 11:22:01.373 - DEBUG<br>
</div>-&gt; &gt; -&gt;<br>
-&gt; &gt; [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:465]<br>
-&gt; &gt; -&gt; - Attempting to select name identifier attribute for relying party &#39;...&#39;<br>
-&gt; &gt; -&gt; that requires format &#39;urn:mace:shibboleth:1.0:nameIdentifier&#39;<br>
-&gt; &gt; -&gt; 11:22:01.374 - DEBUG<br>
-&gt; &gt; -&gt;<br>
-&gt; &gt; [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:548]<br>
-&gt; &gt; -&gt; - Filtering out potential name identifier attributes which do not<br>
-&gt; &gt; support<br>
-&gt; &gt; -&gt; one of the following formats: [urn:mace:shibboleth:1.0:nameIdentifier]<br>
-&gt; &gt; -&gt; 11:22:01.374 - DEBUG<br>
-&gt; &gt; -&gt;<br>
-&gt; &gt; [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:567]<br>
-&gt; &gt; -&gt; - Retaining attribute transientId which may be encoded as a name<br>
-&gt; &gt; identifier<br>
-&gt; &gt; -&gt; of format urn:mace:shibboleth:1.0:nameIdentifier<br>
-&gt; &gt; -&gt; 11:22:01.374 - DEBUG<br>
-&gt; &gt; -&gt;<br>
-&gt; &gt; [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:672]<br>
-&gt; &gt; -&gt; - Selecting attribute to be encoded as a name identifier by encoder of<br>
-&gt; &gt; type<br>
-&gt; &gt; -&gt;<br>
-&gt; &gt; edu.internet2.middleware.shibboleth.common.attribute.encoding.SAML2NameIDEncoder<br>
-&gt; &gt; -&gt; 11:22:01.374 - DEBUG<br>
-&gt; &gt; -&gt;<br>
-&gt; &gt; [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:699]<br>
-&gt; &gt; -&gt; - Selecting the first attribute that can be encoded in to a name<br>
-&gt; &gt; identifier<br>
-&gt; &gt; -&gt; 11:22:01.374 - DEBUG<br>
-&gt; &gt; -&gt;<br>
-&gt; &gt; [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:483]<br>
-&gt; &gt; -&gt; - Name identifier for relying party &#39;...&#39; will be built from attribute<br>
-&gt; &gt; -&gt; &#39;transientId&#39;<br>
-&gt; &gt; -&gt; 11:22:01.374 - DEBUG<br>
-&gt; &gt; -&gt;<br>
-&gt; &gt; [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:864]<br>
-&gt; &gt; -&gt; - Using attribute &#39;transientId&#39; supporting NameID format<br>
-&gt; &gt; -&gt; &#39;urn:oasis:names:tc:SAML:2.0:nameid-format:transient&#39; to create the<br>
-&gt; &gt; NameID<br>
-&gt; &gt; -&gt; for relying party &#39;...&#39;<br>
<div>-&gt; &gt; -&gt;<br>
-&gt; &gt; -&gt; And in the Assertion, it is actually transient NameID.<br>
-&gt; &gt; -&gt;<br>
-&gt; &gt; -&gt; Can you tell me why? Do I need to make any other configuration to be<br>
</div>-&gt; &gt; able<br>
-&gt; &gt; -&gt; to get nameIdentifier?<br>
-&gt; &gt; -&gt;<br>
-&gt; &gt; -&gt;<br>
-&gt; &gt; -&gt; Best,<br>
-&gt; &gt; -&gt; Yaowen<br>
-&gt; &gt; -&gt;<br>
-&gt; &gt; --<br>
-&gt; &gt; To unsubscribe from this list send an email to<br>
-&gt; &gt; <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
-&gt; &gt;<br>
<div><div>-&gt;<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br>