<html><body><div style="color:#000; background-color:#fff; font-family:arial, helvetica, sans-serif;font-size:12pt"><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">I have a school in the UK that wants to use targeted-id as a unique ID for user access.</div><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><br></div><div style="font-family: arial, helvetica, sans-serif; font-size: 16px; color: rgb(0, 0, 0); background-color: transparent; font-style: normal;">I have this in my config:</div><div style="font-family: arial, helvetica, sans-serif; font-size: 16px; color: rgb(0, 0, 0); background-color: transparent; font-style: normal;"><br></div><div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif">&nbsp; &nbsp; &lt;!-- A persistent id attribute that supports personalized anonymous access. --&gt;</font></div><div style="background-color: transparent;"><font face="arial,
 helvetica, sans-serif">&nbsp; &nbsp;&nbsp;</font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif">&nbsp; &nbsp; &lt;!-- First, the deprecated version, decoded as a scoped string: --&gt;</font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif">&nbsp; &nbsp; &lt;Attribute name="urn:mace:dir:attribute-def:eduPersonTargetedID" id="targeted-id"&gt;</font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &lt;AttributeDecoder xsi:type="ScopedAttributeDecoder"/&gt;</font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &lt;!-- &lt;AttributeDecoder xsi:type="NameIDFromScopedAttributeDecoder" formatter="$NameQualifier!$SPNameQualifier!$Name"/&gt; --&gt;</font></div><div style="background-color: transparent;"><font face="arial, helvetica,
 sans-serif">&nbsp; &nbsp; &lt;/Attribute&gt;</font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif">&nbsp; &nbsp;&nbsp;</font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif">&nbsp; &nbsp; &lt;!-- Second, an alternate decoder that will turn the deprecated form into the newer form. --&gt;</font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif">&nbsp; &nbsp; &lt;!--</font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif">&nbsp; &nbsp; &lt;Attribute name="urn:mace:dir:attribute-def:eduPersonTargetedID" id="persistent-id"&gt;</font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &lt;AttributeDecoder xsi:type="NameIDFromScopedAttributeDecoder" formatter="$NameQualifier!$SPNameQualifier!$Name"/&gt;</font></div><div
 style="background-color: transparent;"><font face="arial, helvetica, sans-serif">&nbsp; &nbsp; &lt;/Attribute&gt;</font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif">&nbsp; &nbsp; --&gt;</font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif">&nbsp; &nbsp;&nbsp;</font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif">&nbsp; &nbsp; &lt;!-- Third, the new version (note the OID-style name): --&gt;</font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif">&nbsp; &nbsp; &lt;Attribute name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" id="persistent-id"&gt;</font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &lt;AttributeDecoder xsi:type="NameIDAttributeDecoder"
 formatter="$NameQualifier!$SPNameQualifier!$Name"/&gt;</font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif">&nbsp; &nbsp; &lt;/Attribute&gt;</font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"><br></font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif">&nbsp; &nbsp; &lt;!-- Fourth, the SAML 2.0 NameID Format: --&gt;</font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif">&nbsp; &nbsp; &lt;Attribute name="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" id="persistent-id"&gt;</font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &lt;AttributeDecoder xsi:type="NameIDAttributeDecoder" formatter="$NameQualifier!$SPNameQualifier!$Name"/&gt;</font></div><div style="background-color: transparent;"><font
 face="arial, helvetica, sans-serif">&nbsp; &nbsp; &lt;/Attribute&gt;</font></div><div style="background-color: transparent; color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; font-style: normal;"><font face="arial, helvetica, sans-serif"><br></font></div><div style="background-color: transparent; color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; font-style: normal;"><font face="arial, helvetica, sans-serif"><br></font></div><div style="background-color: transparent; color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; font-style: normal;"><font face="arial, helvetica, sans-serif">Once I have a session with them, I see this:</font></div><div style="background-color: transparent; color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; font-style: normal;"><font face="arial, helvetica, sans-serif"><br></font></div><div style="color: rgb(0, 0,
 0); font-size: 16px; font-family: arial, helvetica, sans-serif; font-style: normal; background-color: transparent;"><font><pre style="background-color: transparent; font-family: arial, helvetica, sans-serif; color: rgb(0, 0, 0); font-size: 16px; font-style: normal;"><u>Miscellaneous</u>
<strong>Client Address:</strong> 12.52.75.130
<strong>Identity Provider:</strong> https://www.login.dumgal.ac.uk/oala/metadata
<strong>SSO Protocol:</strong> urn:oasis:names:tc:SAML:2.0:protocol
<strong>Authentication Time:</strong> 2013-02-18T17:39:59Z
<strong>Authentication Context Class:</strong> (none)
<strong>Authentication Context Decl:</strong> urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified
<strong>Session Expiration (barring inactivity):</strong> 479 minute(s)

<u>Attributes</u>
<strong>affiliation</strong>: member@schoolname.ac.uk
<strong>targeted-id</strong>: C8+gfgfds9876nzl03XdybzI=@schoolname.ac.uk</pre><pre><font face="arial, helvetica, sans-serif" size="4" style="background-color: rgb(255, 255, 255);">So on my protected resource I then expect to see http_targeted-id in the request headers but it is not there. &nbsp;</font></pre><pre><span style="background-color: rgb(255, 255, 255);"><font face="arial, helvetica, sans-serif" size="4">I have asked them to switch to persistent-id for this but </font><font size="4">apparently</font><font face="arial, helvetica, sans-serif" size="4"> they have some challenge with that...</font></span></pre><pre><span style="background-color: rgb(255, 255, 255);"><font face="arial, helvetica, sans-serif" size="4">(stupid Ymail formatting...)</font></span></pre></font></div></div></div></body></html>