Thanks Scott. Does it mean that it is a bug if it returns a  transient NameID instead of nameIdentifier or an error?<br><br>For more information please see the log:<br><br>11:22:01.373 - DEBUG [edu.internet2.middleware.<div id=":j0">

shibboleth.idp.profile.AbstractSAMLProfileHandler:465] - Attempting to select name identifier attribute for relying party &#39;...&#39; that requires format &#39;urn:mace:shibboleth:1.0:nameIdentifier&#39;<br>
11:22:01.374 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:548]
 - Filtering out potential name identifier attributes which do not 
support one of the following formats: [urn:mace:shibboleth:1.0:nameIdentifier]<br>
11:22:01.374 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:567] - <span style="color:rgb(255,0,0)">Retaining attribute transientId which may be encoded as a name identifier of format urn:mace:shibboleth:1.0:</span><span style="color:rgb(255,0,0)">nameIdentifier</span><br>


11:22:01.374 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:672] - Selecting attribute to be encoded as a name identifier by encoder of type edu.internet2.middleware.shibboleth.common.attribute.encoding.SAML2NameIDEncoder<br>


11:22:01.374 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:699] - Selecting the first attribute that can be encoded in to a name identifier<br>11:22:01.374 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:483] - Name identifier for relying party &#39;...&#39; will be built from attribute &#39;transientId&#39;<br>


11:22:01.374 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:864] - <span style="color:rgb(255,0,0)">Using attribute &#39;transientId&#39; supporting NameID format &#39;urn:oasis:names:tc:SAML:2.0:</span><span style="color:rgb(255,0,0)">nameid-format:transient&#39; to create the NameID for relying party &#39;...&#39;</span></div>

<br><br clear="all">Yaowen<br>
<br><br><div class="gmail_quote">On Thu, Aug 2, 2012 at 7:09 AM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">

<div class="im">On 8/1/12 9:10 PM, &quot;Yaowen Tu&quot; &lt;<a href="mailto:yaowen.tu@gmail.com">yaowen.tu@gmail.com</a>&gt; wrote:<br>
&gt;<br>
&gt;In order to comply with the SAML2.0 standards, what should be replied<br>
&gt;from IdP? OOTB Shib IdP will return a NameID with format of<br>
&gt;urn:oasis:names:tc:SAML:2.0:nameid-format:transient.<br>
<br>
<br>
</div>OOTB it should either return what you ask for, or an error, or there&#39;s a<br>
bug.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br>