Thanks Scott. Does it mean that it is a bug if it returns a transient NameID instead of nameIdentifier or an error?<br><br>For more information please see the log:<br><br>11:22:01.373 - DEBUG [edu.internet2.middleware.<div id=":j0">
shibboleth.idp.profile.AbstractSAMLProfileHandler:465] - Attempting to select name identifier attribute for relying party '...' that requires format 'urn:mace:shibboleth:1.0:nameIdentifier'<br>
11:22:01.374 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:548]
- Filtering out potential name identifier attributes which do not
support one of the following formats: [urn:mace:shibboleth:1.0:nameIdentifier]<br>
11:22:01.374 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:567] - <span style="color:rgb(255,0,0)">Retaining attribute transientId which may be encoded as a name identifier of format urn:mace:shibboleth:1.0:</span><span style="color:rgb(255,0,0)">nameIdentifier</span><br>
11:22:01.374 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:672] - Selecting attribute to be encoded as a name identifier by encoder of type edu.internet2.middleware.shibboleth.common.attribute.encoding.SAML2NameIDEncoder<br>
11:22:01.374 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:699] - Selecting the first attribute that can be encoded in to a name identifier<br>11:22:01.374 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:483] - Name identifier for relying party '...' will be built from attribute 'transientId'<br>
11:22:01.374 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:864] - <span style="color:rgb(255,0,0)">Using attribute 'transientId' supporting NameID format 'urn:oasis:names:tc:SAML:2.0:</span><span style="color:rgb(255,0,0)">nameid-format:transient' to create the NameID for relying party '...'</span></div>
<br><br clear="all">Yaowen<br>
<br><br><div class="gmail_quote">On Thu, Aug 2, 2012 at 7:09 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div class="im">On 8/1/12 9:10 PM, "Yaowen Tu" <<a href="mailto:yaowen.tu@gmail.com">yaowen.tu@gmail.com</a>> wrote:<br>
><br>
>In order to comply with the SAML2.0 standards, what should be replied<br>
>from IdP? OOTB Shib IdP will return a NameID with format of<br>
>urn:oasis:names:tc:SAML:2.0:nameid-format:transient.<br>
<br>
<br>
</div>OOTB it should either return what you ask for, or an error, or there's a<br>
bug.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br>