<html><body><div style="color:#000; background-color:#fff; font-family:arial, helvetica, sans-serif;font-size:12pt"><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">I have a school in the UK that wants to use targeted-id as a unique ID for user access.</div><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><br></div><div style="font-family: arial, helvetica, sans-serif; font-size: 16px; color: rgb(0, 0, 0); background-color: transparent; font-style: normal;">I have this in my config:</div><div style="font-family: arial, helvetica, sans-serif; font-size: 16px; color: rgb(0, 0, 0); background-color: transparent; font-style: normal;"><br></div><div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"> <!-- A persistent id attribute that supports personalized anonymous access. --></font></div><div style="background-color: transparent;"><font face="arial,
helvetica, sans-serif"> </font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"> <!-- First, the deprecated version, decoded as a scoped string: --></font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"> <Attribute name="urn:mace:dir:attribute-def:eduPersonTargetedID" id="targeted-id"></font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"> <AttributeDecoder xsi:type="ScopedAttributeDecoder"/></font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"> <!-- <AttributeDecoder xsi:type="NameIDFromScopedAttributeDecoder" formatter="$NameQualifier!$SPNameQualifier!$Name"/> --></font></div><div style="background-color: transparent;"><font face="arial, helvetica,
sans-serif"> </Attribute></font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"> </font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"> <!-- Second, an alternate decoder that will turn the deprecated form into the newer form. --></font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"> <!--</font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"> <Attribute name="urn:mace:dir:attribute-def:eduPersonTargetedID" id="persistent-id"></font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"> <AttributeDecoder xsi:type="NameIDFromScopedAttributeDecoder" formatter="$NameQualifier!$SPNameQualifier!$Name"/></font></div><div
style="background-color: transparent;"><font face="arial, helvetica, sans-serif"> </Attribute></font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"> --></font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"> </font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"> <!-- Third, the new version (note the OID-style name): --></font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"> <Attribute name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" id="persistent-id"></font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"> <AttributeDecoder xsi:type="NameIDAttributeDecoder"
formatter="$NameQualifier!$SPNameQualifier!$Name"/></font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"> </Attribute></font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"><br></font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"> <!-- Fourth, the SAML 2.0 NameID Format: --></font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"> <Attribute name="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" id="persistent-id"></font></div><div style="background-color: transparent;"><font face="arial, helvetica, sans-serif"> <AttributeDecoder xsi:type="NameIDAttributeDecoder" formatter="$NameQualifier!$SPNameQualifier!$Name"/></font></div><div style="background-color: transparent;"><font
face="arial, helvetica, sans-serif"> </Attribute></font></div><div style="background-color: transparent; color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; font-style: normal;"><font face="arial, helvetica, sans-serif"><br></font></div><div style="background-color: transparent; color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; font-style: normal;"><font face="arial, helvetica, sans-serif"><br></font></div><div style="background-color: transparent; color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; font-style: normal;"><font face="arial, helvetica, sans-serif">Once I have a session with them, I see this:</font></div><div style="background-color: transparent; color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; font-style: normal;"><font face="arial, helvetica, sans-serif"><br></font></div><div style="color: rgb(0, 0,
0); font-size: 16px; font-family: arial, helvetica, sans-serif; font-style: normal; background-color: transparent;"><font><pre style="background-color: transparent; font-family: arial, helvetica, sans-serif; color: rgb(0, 0, 0); font-size: 16px; font-style: normal;"><u>Miscellaneous</u>
<strong>Client Address:</strong> 12.52.75.130
<strong>Identity Provider:</strong> https://www.login.dumgal.ac.uk/oala/metadata
<strong>SSO Protocol:</strong> urn:oasis:names:tc:SAML:2.0:protocol
<strong>Authentication Time:</strong> 2013-02-18T17:39:59Z
<strong>Authentication Context Class:</strong> (none)
<strong>Authentication Context Decl:</strong> urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified
<strong>Session Expiration (barring inactivity):</strong> 479 minute(s)
<u>Attributes</u>
<strong>affiliation</strong>: member@schoolname.ac.uk
<strong>targeted-id</strong>: C8+gfgfds9876nzl03XdybzI=@schoolname.ac.uk</pre><pre><font face="arial, helvetica, sans-serif" size="4" style="background-color: rgb(255, 255, 255);">So on my protected resource I then expect to see http_targeted-id in the request headers but it is not there. </font></pre><pre><span style="background-color: rgb(255, 255, 255);"><font face="arial, helvetica, sans-serif" size="4">I have asked them to switch to persistent-id for this but </font><font size="4">apparently</font><font face="arial, helvetica, sans-serif" size="4"> they have some challenge with that...</font></span></pre><pre><span style="background-color: rgb(255, 255, 255);"><font face="arial, helvetica, sans-serif" size="4">(stupid Ymail formatting...)</font></span></pre></font></div></div></div></body></html>